Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, in certain unspecified conditions, does not lock the desktop screen between SPICE sessions, which allows local users with access to a virtual machine to gain access to other users' desktop sessions via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://rhn.redhat.com/errata/RHSA-2012-1508.html | vendor advisory |
http://www.securityfocus.com/bid/56825 | vdb entry |
http://rhn.redhat.com/errata/RHSA-2012-1506.html | vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=754876 | |
http://www.securitytracker.com/id?1027838 | vdb entry |