PT-2010-4306 · Red Hat · Red Hat Enterprise Virtualization
Petr Matousek
·
Published
2010-08-24
·
Updated
2010-08-25
·
CVE-2010-2811
CVSS v2.0
5.7
Medium
| Vector | AV:A/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Red Hat Enterprise Virtualization (RHEV) version 2.2
Description
The issue is related to the Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization (RHEV), which does not properly handle TCP connections for SSL sessions. This allows remote attackers to cause a denial of service, resulting in a daemon outage, by sending crafted SSL traffic.
Recommendations
For Red Hat Enterprise Virtualization (RHEV) version 2.2, consider restricting SSL traffic to trusted sources until a fix is available. As a temporary workaround, limiting the exposure of VDSM to untrusted networks may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat Enterprise Virtualization