<?xml version="1.0" encoding="utf-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Red Hat Security Advisory: rhev-3.1.0 vdsm security, bug fix, and enhancement update</DocumentTitle>
  <DocumentType>Security Advisory</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>secalert@redhat.com</ContactDetails>
    <IssuingAuthority>Red Hat Security Response Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification><ID>RHSA-2012:1508</ID></Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
       <Revision>
         <Number>1</Number>
         <Date>2012-12-04T18:43:00Z</Date>
         <Description>Current version</Description>
       </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2012-12-04T18:43:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2012-12-04T18:43:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>Red Hat rhsa-to-cvrf 1.0.1484</Engine>
      <Date>2012-12-04T19:13:01Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">
Updated vdsm packages are now available for Red Hat Enterprise Linux 6.3.

The Red Hat Security Response Team has rated this update as having
important security impact. Common Vulnerability Scoring System (CVSS) base
scores, which give detailed severity ratings, are available for each
vulnerability from the CVE links in the References section.    </Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
VDSM is a management module that serves as a Red Hat Enterprise
Virtualization Manager agent on Red Hat Enterprise Virtualization
Hypervisor or Red Hat Enterprise Linux 6.3 hosts.

A flaw was found in the way Red Hat Enterprise Linux hosts were added to
the Red Hat Enterprise Virtualization environment. The Python scripts
needed to configure the host for Red Hat Enterprise Virtualization were
stored in the &quot;/tmp/&quot; directory and could be pre-created by an attacker. A
local, unprivileged user on the host to be added to the Red Hat Enterprise
Virtualization environment could use this flaw to escalate their
privileges. This update provides the VDSM part of the fix. The
RHSA-2012:1506 Red Hat Enterprise Virtualization Manager update must also
be installed to completely fix this issue. (CVE-2012-0860)

A flaw was found in the way Red Hat Enterprise Linux and Red Hat Enterprise
Virtualization Hypervisor hosts were added to the Red Hat Enterprise
Virtualization environment. The Python scripts needed to configure the host
for Red Hat Enterprise Virtualization were downloaded in an insecure way,
that is, without properly validating SSL certificates during HTTPS
connections. An attacker on the local network could use this flaw to
conduct a man-in-the-middle attack, potentially gaining root access to the
host being added to the Red Hat Enterprise Virtualization environment. This
update provides the VDSM part of the fix. The RHSA-2012:1506 Red Hat
Enterprise Virtualization Manager update must also be installed to
completely fix this issue. (CVE-2012-0861)

The CVE-2012-0860 and CVE-2012-0861 issues were discovered by Red Hat.

In addition to resolving the above security issues these updated VDSM
packages fix various bugs, and add various enhancements.

Documentation for these bug fixes and enhancements is available in the
Technical Notes:

https://access.redhat.com/knowledge/docs/en-US/Red_Hat_Enterprise_Virtualization/3.1/html/Technical_Notes/index.html

All users who require VDSM are advised to install these updated packages
which resolve these security issues, fix these bugs, and add these
enhancements.    </Note>
    <Note Title="Terms of Use" Ordinal="3" Type="Legal Disclaimer" xml:lang="en">Please see https://www.redhat.com/footer/terms-of-use.html</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
  <AggregateSeverity Namespace="https://access.redhat.com/security/updates/classification/">Important</AggregateSeverity>
  <DocumentReferences>
    <Reference Type="Self">
       <URL>https://rhn.redhat.com/errata/RHSA-2012-1508.html</URL>
       <Description>https://rhn.redhat.com/errata/RHSA-2012-1508.html</Description>
    </Reference>
    <Reference>
       <URL>https://access.redhat.com/security/updates/classification/#important</URL>
       <Description>https://access.redhat.com/security/updates/classification/#important</Description>
    </Reference>
    <Reference>
       <URL>https://access.redhat.com/knowledge/docs/en-US/Red_Hat_Enterprise_Virtualization/3.1/html/Technical_Notes/index.html</URL>
       <Description>https://access.redhat.com/knowledge/docs/en-US/Red_Hat_Enterprise_Virtualization/3.1/html/Technical_Notes/index.html</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=734847</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=734847</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=744704</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=744704</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=772556</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=772556</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=783383</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=783383</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=797526</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=797526</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=798635</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=798635</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=800367</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=800367</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=802759</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=802759</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=806625</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=806625</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=806757</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=806757</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=807351</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=807351</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=807687</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=807687</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=812793</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=812793</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=813423</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=813423</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=814435</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=814435</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=815359</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=815359</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=826467</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=826467</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=826873</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=826873</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=826921</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=826921</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=829037</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=829037</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=829645</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=829645</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=829710</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=829710</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=830485</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=830485</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=830486</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=830486</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=831528</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=831528</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=832765</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=832765</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=832798</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=832798</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=833084</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=833084</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=833099</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=833099</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=833119</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=833119</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=833425</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=833425</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=833803</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=833803</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=834008</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=834008</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=834105</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=834105</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=834205</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=834205</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=835478</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=835478</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=835784</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=835784</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=835900</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=835900</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=835920</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=835920</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=836161</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=836161</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=836562</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=836562</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=836954</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=836954</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=837054</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=837054</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=837836</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=837836</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=838347</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=838347</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=838547</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=838547</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=838802</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=838802</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=838924</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=838924</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=840294</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=840294</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=840300</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=840300</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=840386</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=840386</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=840594</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=840594</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=841863</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=841863</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=842115</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=842115</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=842146</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=842146</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=842338</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=842338</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=842662</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=842662</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=842771</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=842771</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=843076</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=843076</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=843387</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=843387</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=843498</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=843498</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=844180</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=844180</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=844294</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=844294</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=844347</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=844347</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=845193</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=845193</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=845346</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=845346</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=845525</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=845525</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=845830</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=845830</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=846004</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=846004</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=846014</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=846014</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=846307</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=846307</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=846312</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=846312</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=846323</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=846323</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=846376</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=846376</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=847518</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=847518</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=847733</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=847733</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=847744</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=847744</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=848101</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=848101</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=848299</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=848299</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=848616</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=848616</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=848728</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=848728</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=849315</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=849315</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=849542</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=849542</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=851146</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=851146</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=851839</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=851839</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=852989</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=852989</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=853011</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=853011</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=853040</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=853040</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=853703</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=853703</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=853710</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=853710</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=853910</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=853910</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=853968</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=853968</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=854027</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=854027</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=854151</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=854151</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=854212</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=854212</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=854242</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=854242</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=854457</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=854457</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=854748</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=854748</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=854763</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=854763</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=854765</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=854765</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=854919</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=854919</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=854953</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=854953</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=855049</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=855049</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=855425</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=855425</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=855729</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=855729</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=855887</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=855887</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=855918</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=855918</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=855922</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=855922</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=855924</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=855924</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=856163</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=856163</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=856167</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=856167</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=857112</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=857112</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=859109</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=859109</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=862002</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=862002</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=863265</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=863265</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=865386</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=865386</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=866163</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=866163</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=866533</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=866533</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=867354</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=867354</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=867806</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=867806</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=867813</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=867813</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=867922</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=867922</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=868272</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=868272</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=868681</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=868681</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=868721</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=868721</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=870024</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=870024</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=870079</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=870079</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=870734</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=870734</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=870768</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=870768</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=871355</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=871355</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=871811</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=871811</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=872270</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=872270</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=872935</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=872935</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=874481</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=874481</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=876115</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=876115</Description>
    </Reference>
    <Reference>
       <URL>https://bugzilla.redhat.com/show_bug.cgi?id=876558</URL>
       <Description>https://bugzilla.redhat.com/show_bug.cgi?id=876558</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="Red Hat Enterprise Virtualization">
      <Branch Type="Product Name" Name="RHEV Agents (vdsm)">
        <FullProductName ProductID="6Server-RHEV-Agents">RHEV Agents (vdsm)</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="vdsm-4.9.6-44.0.el6_3">
      <FullProductName ProductID="vdsm-4.9.6-44.0.el6_3">vdsm-4.9.6-44.0.el6_3.src.rpm</FullProductName>
    </Branch>
    <Relationship ProductReference="vdsm-4.9.6-44.0.el6_3" RelationType="Default Component Of" RelatesToProductReference="6Server-RHEV-Agents">
      <FullProductName ProductID="6Server-RHEV-Agents:vdsm-4.9.6-44.0.el6_3">vdsm-4.9.6-44.0.el6_3 as a component of RHEV Agents (vdsm)</FullProductName>
    </Relationship>
  </ProductTree>

  <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the way Red Hat Enterprise Linux hosts were added to the Red Hat Enterprise Virtualization environment. The Python scripts needed to configure the host for Red Hat Enterprise Virtualization were stored in the &quot;/tmp/&quot; directory and could be pre-created by an attacker. A local, unprivileged user on the host to be added to the Red Hat Enterprise Virtualization environment could use this flaw to escalate their privileges. This update provides the VDSM part of the fix. The RHSA-2012:1506 Red Hat Enterprise Virtualization Manager update must also be installed to completely fix this issue. 
The CVE-2012-0860 and CVE-2012-0861 issues were discovered by Red Hat.</Note></Notes>
    <DiscoveryDate>2012-02-14T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-12-04T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-0860</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-RHEV-Agents:vdsm-4.9.6-44.0.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Important</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>6.2</BaseScore>
      <Vector>AV:L/AC:H/Au:N/C:C/I:C/A:C</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1508.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-0860.html</URL>
        <Description>CVE-2012-0860</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=790730</URL>
        <Description>bz#790730: CVE-2012-0860 rhev: vds_installer insecure /tmp use</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the way Red Hat Enterprise Linux and Red Hat Enterprise Virtualization Hypervisor hosts were added to the Red Hat Enterprise Virtualization environment. The Python scripts needed to configure the host for Red Hat Enterprise Virtualization were downloaded in an insecure way, that is, without properly validating SSL certificates during HTTPS connections. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, potentially gaining root access to the host being added to the Red Hat Enterprise Virtualization environment. This update provides the VDSM part of the fix. The RHSA-2012:1506 Red Hat Enterprise Virtualization Manager update must also be installed to completely fix this issue. 
The CVE-2012-0860 and CVE-2012-0861 issues were discovered by Red Hat.</Note></Notes>
    <DiscoveryDate>2012-02-15T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-12-04T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-0861</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-RHEV-Agents:vdsm-4.9.6-44.0.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Important</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>6.8</BaseScore>
      <Vector>AV:A/AC:H/Au:N/C:C/I:C/A:C</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1508.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-0861.html</URL>
        <Description>CVE-2012-0861</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=790754</URL>
        <Description>bz#790754: CVE-2012-0861 rhev: vds_installer is prone to MITM when downloading 2nd stage installer</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
