First published: Fri Nov 18 2011(Updated: )
It was found that under certain conditions, SPICE would fail to lock the screen on a virtual machine between sessions. A user with access to a virtual machine in the Red Hat Enterprise Virtualization Manager could exploit this flaw to gain access to another user's unlocked desktop session. This is a security concern in environments where multiple users have access to the same virtual machine, but they use different operating system credentials to log on to that virtual machine.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Virtualization Manager | <=3.0 | |
Red Hat Enterprise Virtualization Manager | =2.1 | |
Red Hat Enterprise Virtualization Manager | =2.2 | |
Red Hat Enterprise Virtualization Manager | =2.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4316 is classified as a medium severity vulnerability.
To fix CVE-2011-4316, you should update the affected Red Hat Enterprise Virtualization Manager to the latest version available.
CVE-2011-4316 affects users of Red Hat Enterprise Virtualization Manager versions up to 3.0 and versions 2.1, 2.2, and 2.2.3.
Exploitation of CVE-2011-4316 could allow an unauthorized user to access another user's unlocked desktop session on a virtual machine.
CVE-2011-4316 was published in late 2011.