CVE-2014-7813: Medium severity red hat cloudforms management engine vulnerability
Aaron Patterson of Red Hat reports:
There are a number of locations in the code where .tosym is called on user supplied code, resulting in a potential DoS condition as an attacker can insert symbols that are never garbage collected.
Other sources
Red Hat CloudForms 3 Management Engine (CFME) allows remote authenticated users to cause a denial of service (resource consumption) via vectors involving calls to the .tosym rails function and lack of garbage collection of inserted symbols.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7813?
CVE-2014-7813 is categorized as a moderate severity vulnerability.
How do I fix CVE-2014-7813?
To fix CVE-2014-7813, update to the latest version of Red Hat CloudForms Management Engine that addresses this issue.
What type of vulnerability is CVE-2014-7813?
CVE-2014-7813 is a denial-of-service (DoS) vulnerability due to improper handling of user-supplied code.
What systems are affected by CVE-2014-7813?
CVE-2014-7813 affects Red Hat CloudForms 3.0 Management Engine.
Can CVE-2014-7813 be exploited remotely?
Yes, CVE-2014-7813 can potentially be exploited remotely by an attacker.