CVE-2014-0189: Low severity redhat Enterprise Linux Desktop vulnerability
It was reported that "/etc/sysconfig/virt-who" is world-readable and contains plaintext passwords to connect to various hypervisors. A local attacker could use this flaw to obtain those passwords and gain access to the hypervisors.
Other sources
virt-who uses world-readable permissions for /etc/sysconfig/virt-who, which allows local users to obtain password for hypervisors by reading the file.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0189?
CVE-2014-0189 is considered a moderate severity vulnerability due to the risk of local attackers gaining access to sensitive information.
How do I fix CVE-2014-0189?
To fix CVE-2014-0189, change the permissions of the '/etc/sysconfig/virt-who' file to restrict access to authorized users only.
What systems are affected by CVE-2014-0189?
CVE-2014-0189 affects Red Hat Enterprise Linux 7.0 and systems running the Virt-who application.
What data is compromised in CVE-2014-0189?
CVE-2014-0189 compromises plaintext passwords used to connect to hypervisors, which can lead to unauthorized access.
Can CVE-2014-0189 be exploited remotely?
CVE-2014-0189 cannot be exploited remotely; it requires local access to the system to read the world-readable file.