The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted XML/RSDL document, related to an XML External Entity (XXE) issue.
References
Link | Resource |
---|---|
http://rhn.redhat.com/errata/RHSA-2014-1161.html | Vendor Advisory |
http://www.securitytracker.com/id/1030807 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2014-10-18T00:00:00
Updated: 2014-10-17T23:57:00
Reserved: 2014-05-14T00:00:00
Link: CVE-2014-3573
JSON object: View
NVD Information
Status : Modified
Published: 2014-10-18T00:55:04.690
Modified: 2023-02-13T00:40:47.610
Link: CVE-2014-3573
JSON object: View
Redhat Information
No data.
CWE