CVE-2016-5411: Critical severity red hat quickstart cloud installer vulnerability
/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the root password of the deployed system.
Other sources
Thom Carlin of Red Hat report:
The file /var/lib/ovirt-engine/setup/engine-DC-config.py is created world readable and contains the root password for the deployed system.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5411?
CVE-2016-5411 has a high severity due to the exposure of the root password in a world-readable file.
How do I fix CVE-2016-5411?
To fix CVE-2016-5411, restrict permissions on the file /var/lib/ovirt-engine/setup/engine-DC-config.py to prevent unauthorized access.
Which versions of QuickStart Cloud Installer are affected by CVE-2016-5411?
CVE-2016-5411 affects Red Hat QuickStart Cloud Installer version 0.9.
What are the consequences of CVE-2016-5411?
The consequences of CVE-2016-5411 include potential unauthorized access to the root password, leading to compromised systems.
Is this vulnerability present in Red Hat Enterprise Linux?
CVE-2016-5411 is specifically related to Red Hat QuickStart Cloud Installer and does not affect Red Hat Enterprise Linux.