Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a virtual machine's data, which allows guest OS users to obtain sensitive information by examining the disk blocks associated with a deleted virtual machine.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://rhn.redhat.com/errata/RHSA-2010-0476.html | patch vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=604752 | |
http://www.securityfocus.com/bid/41044 | vdb entry |
https://rhn.redhat.com/errata/RHSA-2010-0473.html | patch vendor advisory |
http://securitytracker.com/id?1024137 | vdb entry |