CVE-2015-0257: Low severity red hat enterprise virtualization manager vulnerability
Published May 1, 2015
·Updated
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory.
Affected Software
1 affected component
redhat Enterprise Virtualization Manager<=3.5.0
Event History
May 1, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0257?
CVE-2015-0257 has a moderate severity rating due to the exposure of sensitive information to local users.
2
How do I fix CVE-2015-0257?
To fix CVE-2015-0257, upgrade your Red Hat Enterprise Virtualization Manager to version 3.5.1 or later.
3
Who is affected by CVE-2015-0257?
CVE-2015-0257 affects users of Red Hat Enterprise Virtualization Manager versions prior to 3.5.1.
4
What kind of information can be exposed due to CVE-2015-0257?
CVE-2015-0257 allows local users to read files containing sensitive information in weakly permissioned directories.
5
When was CVE-2015-0257 reported?
CVE-2015-0257 was reported and made public in 2015.