CVE-2012-5516: Infoleak
Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when moving disks between storage domains, does not properly wipe-after-delete, which prevents disks from being securely deleted and might allow local users to obtain sensitive information via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5516?
CVE-2012-5516 has a Medium severity due to its potential to expose sensitive information.
How do I fix CVE-2012-5516?
To fix CVE-2012-5516, upgrade Red Hat Enterprise Virtualization Manager to version 3.1 or later.
Which versions of Red Hat Enterprise Virtualization Manager are affected by CVE-2012-5516?
CVE-2012-5516 affects Red Hat Enterprise Virtualization Manager versions 2.1, 2.2, 2.2.3, 2.2.4, and all versions up to 3.0.
What type of vulnerability is CVE-2012-5516?
CVE-2012-5516 is a data protection vulnerability related to improper secure deletion of disks.
Can local users exploit CVE-2012-5516?
Yes, local users can potentially exploit CVE-2012-5516 to obtain sensitive information from improperly deleted disks.