Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a virtual machine's data, which allows guest OS users to obtain sensitive information by examining the disk blocks associated with a deleted virtual machine.
References
Link | Resource |
---|---|
http://securitytracker.com/id?1024137 | |
http://www.securityfocus.com/bid/41044 | |
https://bugzilla.redhat.com/show_bug.cgi?id=604752 | |
https://rhn.redhat.com/errata/RHSA-2010-0473.html | Patch Vendor Advisory |
https://rhn.redhat.com/errata/RHSA-2010-0476.html | Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2010-06-24T17:00:00Z
Updated: 2010-06-24T17:00:00Z
Reserved: 2010-06-09T00:00:00Z
Link: CVE-2010-2223
JSON object: View
NVD Information
Status : Analyzed
Published: 2010-06-24T17:30:00.937
Modified: 2010-06-25T04:00:00.000
Link: CVE-2010-2223
JSON object: View
Redhat Information
No data.
CWE