First published: Fri Nov 18 2011(Updated: )
It was found that under certain conditions, SPICE would fail to lock the screen on a virtual machine between sessions. A user with access to a virtual machine in the Red Hat Enterprise Virtualization Manager could exploit this flaw to gain access to another user's unlocked desktop session. This is a security concern in environments where multiple users have access to the same virtual machine, but they use different operating system credentials to log on to that virtual machine.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Enterprise Virtualization Manager | =2.1 | |
Redhat Enterprise Virtualization Manager | =2.2.3 | |
Redhat Enterprise Virtualization Manager | =2.2 | |
Redhat Enterprise Virtualization Manager | <=3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.