PT-2010-4295 · Red Hat · Spice+2
Petr Matousek
·
Publicado
2010-08-25
·
Atualizado
2024-03-12
·
CVE-2010-2792
CVSS v2.0
3.3
Baixa
| Vetor | AV:L/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SPICE (aka spice-xpi) plug-in versions 2.2
qspice version 0.3.0
Description
The issue allows local users to obtain sensitive information and conduct man-in-the-middle attacks by providing a UNIX socket for communication between the SPICE plug-in and the client in qspice, and then accessing this socket.
Recommendations
For SPICE (aka spice-xpi) plug-in version 2.2, consider restricting access to the UNIX socket used for communication between the plug-in and the client to minimize the risk of exploitation.
For qspice version 0.3.0, restrict access to the client (aka qspice-client) to prevent unauthorized access to the UNIX socket.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Race Condition
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Spice
Qspice