First published: Wed Jan 09 2013(Updated: )
A flaw was found in the way MoveDisk command checks permissions on target storage domain. A privileged user (storage admin of other storage domain) can use this flaw to conduct denial of service attack on the target domain by exhausting the available free space. Acknowledgements: This issue was discovered by Ondrej Machacek of Red Hat.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Virtualization Manager | <=3.1 | |
Red Hat Enterprise Virtualization Manager | =2.1 | |
Red Hat Enterprise Virtualization Manager | =2.2 | |
Red Hat Enterprise Virtualization Manager | =2.2.3 | |
Red Hat Enterprise Virtualization Manager | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0168 is considered a high severity vulnerability due to its potential for denial of service attacks.
CVE-2013-0168 affects multiple versions of Red Hat Enterprise Virtualization Manager by allowing privileged users to exhaust free space in storage domains.
To fix CVE-2013-0168, ensure that you are running the latest patched version of Red Hat Enterprise Virtualization Manager.
Storage admins with privileged access in Red Hat Enterprise Virtualization Manager installations are affected by CVE-2013-0168.
Exploiting CVE-2013-0168 can lead to a denial of service by filling up the available free space in a target storage domain.