The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which allows man-in-the-middle attackers to spoof the SPICE server.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/65077 | vdb entry |
http://www.securitytracker.com/id/1029653 | vdb entry |
http://rhn.redhat.com/errata/RHSA-2014-0038.html | vendor advisory |