RSS   Vulnerabilities for 'Ovirt-node'   RSS

2017-09-25
 
CVE-2014-8170

 

 
ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote authenticated users and physically proximate attackers to execute arbitrary commands via a ; (semicolon) in an input string.

 

 >>> Vendor: Ovirt 10 Products
Ovirt
Ovirt-engine-cli
Sanlock
Ovirt-node
Ovirt-hosted-engine-setup
VDSM
Cockpit-ovirt
Ovirt-engine
MOM
NODE


Copyright 2024, cxsecurity.com

 

Back to Top