REDHAT-BUG-606774: Medium severity red hat enterprise virtualization manager (rhev-m) vulnerability
It was found that Red Hat Enterprise Virtualization Manager did not correctly pass the postzero parameter for deleted volumes after snapshot merging. This resulted in such volumes not being securely deleted as expected. A guest user in a new, raw virtual machine (VM), created in a data domain that has had VMs deleted from it, could use this flaw to read limited data from those deleted VMs, potentially disclosing sensitive information. (CVE-2010-2224)
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-606774?
The severity of REDHAT-BUG-606774 is considered important as it involves improper deletion of sensitive data.
How do I fix REDHAT-BUG-606774?
To fix REDHAT-BUG-606774, you need to apply the latest patches and updates provided by Red Hat for the Enterprise Virtualization Manager.
What systems are affected by REDHAT-BUG-606774?
REDHAT-BUG-606774 affects systems running Red Hat Enterprise Virtualization Manager.
What are the potential risks of REDHAT-BUG-606774?
The risks associated with REDHAT-BUG-606774 include unauthorized access to deleted data through improperly managed virtual machines.
Can a guest user exploit REDHAT-BUG-606774?
Yes, a guest user could potentially exploit REDHAT-BUG-606774 to access undeleted data from deleted volumes.