CVE-2014-0189

virt-who - Info Disclosure

Title source: llm
STIX 2.1

Description

virt-who uses world-readable permissions for /etc/sysconfig/virt-who, which allows local users to obtain password for hypervisors by reading the file.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/67089
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1088732
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/04/28/2
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1081286
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0430.html

Scores

EPSS 0.0039
EPSS Percentile 31.0%

Details

CWE
CWE-310
Status published
Products (4)
redhat/enterprise_linux_desktop 7.0
redhat/enterprise_linux_server 7.0
redhat/enterprise_linux_workstation 7.0
virt-who_project/virt-who
Published May 02, 2014
Tracked Since Feb 18, 2026