CVE-2012-0861: Medium severity red hat enterprise virtualization manager vulnerability
The vdsinstaller in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading deployUtil.py and vdsbootstrap.py, which prevents SSL certificates from being validated and allows remote attackers to execute arbitrary Python code via a man-in-the-middle attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0861?
CVE-2012-0861 has a medium severity due to the potential for remote code execution.
How do I fix CVE-2012-0861?
To fix CVE-2012-0861, upgrade Red Hat Enterprise Virtualization Manager to version 3.1 or later.
What are the potential consequences of CVE-2012-0861?
CVE-2012-0861 allows remote attackers to execute arbitrary Python code, leading to potential system compromise.
Which versions of Red Hat Enterprise Virtualization Manager are affected by CVE-2012-0861?
CVE-2012-0861 affects versions 2.1, 2.2, 2.2.3, and all versions up to 3.0 of Red Hat Enterprise Virtualization Manager.
Is there a workaround for CVE-2012-0861 if I cannot upgrade?
There are no official workarounds for CVE-2012-0861; the recommended action is to upgrade to a secure version.