CVE-2013-2144: Medium severity red hat enterprise virtualization manager vulnerability
Red Hat Enterprise Virtualization Manager (RHEVM) before 3.2 does not properly check permissions for the target storage domain, which allows attackers to cause a denial of service (disk space consumption) by cloning a VM from a snapshot.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2144?
CVE-2013-2144 is classified as a medium severity vulnerability due to potential denial of service through disk space consumption.
How do I fix CVE-2013-2144?
To fix CVE-2013-2144, upgrade Red Hat Enterprise Virtualization Manager to version 3.2 or later.
What are the affected versions of Red Hat Enterprise Virtualization Manager for CVE-2013-2144?
CVE-2013-2144 affects versions of Red Hat Enterprise Virtualization Manager prior to 3.2, including 2.1, 2.2, 2.2.3, and 3.0.
What kind of attack can be executed using CVE-2013-2144?
An attacker can exploit CVE-2013-2144 to cause a denial of service by cloning a virtual machine from a snapshot to consume disk space.
Is user permission checking impacted in CVE-2013-2144?
Yes, CVE-2013-2144 reveals improper permission checks for the target storage domain in Red Hat Enterprise Virtualization Manager.