CVE-2010-2792: Race Condition
Race condition in the SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to obtain sensitive information, and conduct man-in-the-middle attacks, by providing a UNIX socket for communication between this plug-in and the client (aka qspice-client) in qspice 0.3.0, and then accessing this socket.
Other sources
There is a race in spice-xpi when a local attacker is able to create a unix socket with the expected name that is used for parameter passing (password, cert file) between spice-xpi and spice client.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2792?
CVE-2010-2792 is classified as a medium severity vulnerability due to its potential to allow local users to access sensitive information.
How do I fix CVE-2010-2792?
To mitigate CVE-2010-2792, users should update to the latest version of the SPICE plug-in provided by Red Hat.
What systems are affected by CVE-2010-2792?
CVE-2010-2792 specifically affects users of the SPICE plug-in version 2.2 on compatible systems.
Can CVE-2010-2792 lead to a man-in-the-middle attack?
Yes, CVE-2010-2792 can be exploited to conduct man-in-the-middle attacks due to a race condition in the SPICE plug-in.
Who is responsible for addressing CVE-2010-2792?
The responsibility for addressing CVE-2010-2792 lies with Red Hat and users of the affected SPICE plug-in.