CVE-2015-0257

Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:enterprise_virtualization_manager:*:*:*:*:*:*:*:*

History

12 Feb 2023, 23:15

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2015-0257', 'name': 'https://access.redhat.com/security/cve/CVE-2015-0257', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:0888', 'name': 'https://access.redhat.com/errata/RHSA-2015:0888', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1189085', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1189085', 'tags': [], 'refsource': 'MISC'}
Summary It was discovered that a directory shared between the ovirt-engine-dwhd service and a plug-in used during the service's startup had incorrect permissions. A local user could use this flaw to access files in this directory, which could potentially contain sensitive information. Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory.

02 Feb 2023, 16:16

Type Values Removed Values Added
Summary Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory. It was discovered that a directory shared between the ovirt-engine-dwhd service and a plug-in used during the service's startup had incorrect permissions. A local user could use this flaw to access files in this directory, which could potentially contain sensitive information.
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2015-0257 -
  • (MISC) https://access.redhat.com/errata/RHSA-2015:0888 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1189085 -

Information

Published : 2015-05-01 15:59

Updated : 2023-12-10 11:31


NVD link : CVE-2015-0257

Mitre link : CVE-2015-0257

CVE.ORG link : CVE-2015-0257


JSON object : View

Products Affected

redhat

  • enterprise_virtualization_manager
CWE
CWE-264

Permissions, Privileges, and Access Controls