virt-who: information leak
| Package(s): | virt-who | CVE #(s): | CVE-2014-0189 | ||||||||||||
| Created: | February 16, 2015 | Updated: | March 6, 2015 | ||||||||||||
| Description: | From the CVE entry:
virt-who uses world-readable permissions for /etc/sysconfig/virt-who, which allows local users to obtain password for hypervisors by reading the file. | ||||||||||||||
| Alerts: |
| ||||||||||||||
