It was found that fix for CVE-2013-0167 was not complete. A privileged guest user could still potentially make the host the guest is running on unavailable to the management server by making guest agent return data with invalid XML characters.
Upstream fix: http://gerrit.ovirt.org/gitweb?p=vdsm.git;a=commit;h=5fe1615b7949999fc9abd896bde63bf24f8431d6
Acknowledgements:
This issue was found by David Gibson of Red Hat.
A cross-site scripting (XSS) flaw was found in the RedirectServlet of the oVirt Engine and Red Hat Enterprise Virtualization Manager (RHEV-M). A remote attacker could provide a specially-crafted link, that when visited by an unsuspecting RHEV-M / oVirt user would lead to arbitrary script execution in the context of the RHEV-M / oVirt domain. Access to the RedirectServlet does not require authentication.
An unquoted search path flaw was found in the way Spice service for Windows was installed into the system.
A local unprivileged user could use this flaw to increase their privileges.
References:
http://cwe.mitre.org/data/definitions/428.html
Unquoted Windows search path vulnerability in Red Hat Enterprise Virtualization (RHEV) 3 and 3.2 allows local users to gain privileges via a crafted application in an unspecified folder.
A flaw was found in the way processing of unexpected fields in guestInfo dictionary were handled. A privileged guest user can potentially make the host the VM runs on unavailable to the managment server.
Acknowledgements:
This issue was discovered by Dan Kenigsberg of the Red Hat Enterprise Virtualization team.