PT-2010-4306 · Red Hat · Red Hat Enterprise Virtualization
Petr Matousek
·
Publicado
2010-08-24
·
Atualizado
2010-08-25
·
CVE-2010-2811
CVSS v2.0
5.7
Média
| Vetor | AV:A/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Red Hat Enterprise Virtualization (RHEV) version 2.2
Description
The issue is related to the Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization (RHEV), which does not properly handle TCP connections for SSL sessions. This allows remote attackers to cause a denial of service, resulting in a daemon outage, by sending crafted SSL traffic.
Recommendations
For Red Hat Enterprise Virtualization (RHEV) version 2.2, consider restricting SSL traffic to trusted sources until a fix is available. As a temporary workaround, limiting the exposure of VDSM to untrusted networks may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Red Hat Enterprise Virtualization