First published: Sat Aug 15 2015(Updated: )
Michal Skrivanek of Red Hat reports: If vdsm is run with -spice disable-ticketing and a VM is suspended and then restored any remote user will be allowed to connect without authentication.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Virtualization | <3.5.6 | |
Red Hat Enterprise Virtualization Hypervisor | >=6-6.0<6-6.7-20151117.0 | |
Red Hat Enterprise Virtualization Hypervisor | >=7-7.0<7-7.2-20151119.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-5201 is rated as high due to the potential for unauthorized remote access.
To fix CVE-2015-5201, upgrade to the latest version of Red Hat Enterprise Virtualization or Red Hat Enterprise Virtualization Hypervisor that addresses this vulnerability.
CVE-2015-5201 affects multiple versions of Red Hat Enterprise Virtualization and Red Hat Enterprise Virtualization Hypervisor before respective patch versions.
CVE-2015-5201 allows any remote user to connect to a suspended virtual machine without authentication, compromising its security.
The recommended workaround for CVE-2015-5201 is to avoid using the '-spice disable-ticketing' option until a fix is applied.