CVE-2013-0168: Medium severity red hat enterprise virtualization manager vulnerability
A flaw was found in the way MoveDisk command checks permissions on target storage domain. A privileged user (storage admin of other storage domain) can use this flaw to conduct denial of service attack on the target domain by exhausting the available free space.
Acknowledgements:
This issue was discovered by Ondrej Machacek of Red Hat.
Other sources
The MoveDisk command in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier does not properly check permissions on storage domains, which allows remote authenticated storage admins to cause a denial of service (free space consumption of other storage domains) via unspecified vectors.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0168?
CVE-2013-0168 is considered a high severity vulnerability due to its potential for denial of service attacks.
How does CVE-2013-0168 affect Red Hat Enterprise Virtualization Manager?
CVE-2013-0168 affects multiple versions of Red Hat Enterprise Virtualization Manager by allowing privileged users to exhaust free space in storage domains.
How do I fix CVE-2013-0168?
To fix CVE-2013-0168, ensure that you are running the latest patched version of Red Hat Enterprise Virtualization Manager.
Who is affected by CVE-2013-0168?
Storage admins with privileged access in Red Hat Enterprise Virtualization Manager installations are affected by CVE-2013-0168.
What is the impact of exploiting CVE-2013-0168?
Exploiting CVE-2013-0168 can lead to a denial of service by filling up the available free space in a target storage domain.