CVE-2014-0189

virt-who uses world-readable permissions for /etc/sysconfig/virt-who, which allows local users to obtain password for hypervisors by reading the file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:virt-who_project:virt-who:-:*:*:*:*:*:*:*

History

13 Feb 2023, 00:36

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2014-0189', 'name': 'https://access.redhat.com/security/cve/CVE-2014-0189', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:0430', 'name': 'https://access.redhat.com/errata/RHSA-2015:0430', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHBA-2014:1513', 'name': 'https://access.redhat.com/errata/RHBA-2014:1513', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHBA-2014:1206', 'name': 'https://access.redhat.com/errata/RHBA-2014:1206', 'tags': [], 'refsource': 'MISC'}
Summary It was discovered that the /etc/sysconfig/virt-who configuration file, which may contain hypervisor authentication credentials, was world-readable. A local user could use this flaw to obtain authentication credentials from this file. virt-who uses world-readable permissions for /etc/sysconfig/virt-who, which allows local users to obtain password for hypervisors by reading the file.

02 Feb 2023, 20:16

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2014-0189 -
  • (MISC) https://access.redhat.com/errata/RHSA-2015:0430 -
  • (MISC) https://access.redhat.com/errata/RHBA-2014:1513 -
  • (MISC) https://access.redhat.com/errata/RHBA-2014:1206 -
Summary virt-who uses world-readable permissions for /etc/sysconfig/virt-who, which allows local users to obtain password for hypervisors by reading the file. It was discovered that the /etc/sysconfig/virt-who configuration file, which may contain hypervisor authentication credentials, was world-readable. A local user could use this flaw to obtain authentication credentials from this file.

Information

Published : 2014-05-02 14:55

Updated : 2023-12-10 11:31


NVD link : CVE-2014-0189

Mitre link : CVE-2014-0189

CVE.ORG link : CVE-2014-0189


JSON object : View

Products Affected

redhat

  • enterprise_linux_desktop
  • enterprise_linux_workstation
  • enterprise_linux_server

virt-who_project

  • virt-who
CWE
CWE-310

Cryptographic Issues