PT-2013-1519 · Red Hat · Red Hat Enterprise Virtualization Manager

Published

2013-01-04

·

Updated

2023-02-13

·

CVE-2012-0861

CVSS v2.0

6.8

Medium

VectorAV:A/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Virtualization Manager (RHEV-M) versions prior to 3.1
Description The issue concerns the use of the -k curl parameter by the vds installer when adding a host, which prevents SSL certificates from being validated. This allows remote attackers to execute arbitrary Python code via a man-in-the-middle attack.
Recommendations For versions prior to 3.1, update to version 3.1 or later to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2012-0861
RHSA-2012:1505
RHSA-2012:1506
RHSA-2012:1508

Affected Products

Red Hat Enterprise Virtualization Manager