Home page logo

oss-sec logo oss-sec mailing list archives

CVE Request -- vdsm: incomplete fix for CVE-2013-0167 issue
From: Petr Matousek <pmatouse () redhat com>
Date: Mon, 12 Aug 2013 16:44:08 +0200

It was found that fix for CVE-2013-0167 was not complete. A privileged
guest user could still potentially make the host the guest is running on
unavailable to the management server by making guest agent return data
with invalid XML characters.

Upstream fix:


Petr Matousek / Red Hat Security Response Team

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]