First published: Fri Jan 04 2013(Updated: )
Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when moving disks between storage domains, does not properly wipe-after-delete, which prevents disks from being securely deleted and might allow local users to obtain sensitive information via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Virtualization Manager | <=3.0 | |
Red Hat Enterprise Virtualization Manager | =2.1 | |
Red Hat Enterprise Virtualization Manager | =2.2 | |
Red Hat Enterprise Virtualization Manager | =2.2.3 | |
Red Hat Enterprise Virtualization Manager | =2.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5516 has a Medium severity due to its potential to expose sensitive information.
To fix CVE-2012-5516, upgrade Red Hat Enterprise Virtualization Manager to version 3.1 or later.
CVE-2012-5516 affects Red Hat Enterprise Virtualization Manager versions 2.1, 2.2, 2.2.3, 2.2.4, and all versions up to 3.0.
CVE-2012-5516 is a data protection vulnerability related to improper secure deletion of disks.
Yes, local users can potentially exploit CVE-2012-5516 to obtain sensitive information from improperly deleted disks.