Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
http://securitytracker.com/id?1024825 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=620355 | |
http://www.securityfocus.com/bid/45213 | vdb entry |
https://rhn.redhat.com/errata/RHSA-2010-0818.html | vendor advisory |