- Issued:
- 2013-09-10
- Updated:
- 2013-09-10
RHSA-2013:1210 - Security Advisory
Synopsis
Moderate: rhevm security and bug fix update
Type/Severity
Security Advisory: Moderate
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
Updated rhevm packages that fix one security issue and various bugs are now
available.
The Red Hat Security Response Team has rated this update as having moderate
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.
Description
The Red Hat Enterprise Virtualization Manager is a centralized management
platform that allows system administrators to view and manage virtual
machines. The Manager provides a comprehensive range of features including
search capabilities, resource management, live migrations, and virtual
infrastructure provisioning.
The Manager is a JBoss Application Server application that provides several
interfaces through which the virtual environment can be accessed and
interacted with, including an Administration Portal, a User Portal, and a
Representational State Transfer (REST) Application Programming Interface
(API).
A reflected cross-site scripting (XSS) flaw was found in Red Hat Enterprise
Virtualization Manager. An attacker could construct a carefully-crafted
URL, which once visited by an unsuspecting user, could cause the user's web
browser to execute malicious script in the context of the Red Hat
Enterprise Virtualization Manager domain. (CVE-2013-4181)
Red Hat would like to thank Kayhan KAYIHAN of Endersys A.Ş. for reporting
this issue.
A list of the bugs fixed in this update is available in the Technical Notes
document:
All Red Hat Enterprise Virtualization Manager users are advised to upgrade
to these updated packages, which resolve these issues.
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/site/articles/11258
Further information on upgrading the Red Hat Enterprise Virtualization
Manager is available in the Installation Guide:
https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Virtualization/3.2/html/Installation_Guide/Upgrading_between_Minor_Releases.html
Affected Products
- Red Hat Virtualization 3.2 x86_64
Fixes
- BZ - 988048 - Underscores in tag names break tags
- BZ - 988774 - CVE-2013-4181 ovirt-engine: RedirectServlet cross-site scripting flaw
- BZ - 991542 - [LSM] engine: disk remains in locked state with repeating error in engine log when vm's pid is suddenly killed
- BZ - 993014 - [RHEV+RHS] Volume created for VM Image Store, on Red Hat Storage nodes added to 'Gluster Enabled Cluster', cannot be added as Storage Domain, to POSIX compliant FS Data Center, possibly due to firewall block
- BZ - 994100 - unit-tests need to fix occasional NPE failure in WebAdminHostPageServletTest
- BZ - 996125 - [engine] Display type is not inherited correctly from templates
- BZ - 996127 - Windows XP guest fails to start when enabling native USB support.
- BZ - 996854 - [host-deploy] block concurrent installation for same host
- BZ - 996970 - Changing email address for event notification results in error "User is already subscribed to this event with the same Notification method"
- BZ - 997394 - [rhevm-manage-domains] /var/log/ovirt-engine/engine-manage-domains.log doesn't exist
- BZ - 997426 - There is no notifier.log generation
- BZ - 998240 - Attaching a network to a host's nic inherits the host nic's IP to the new network
- BZ - 998254 - User can't see networks in DC when he has NetworkUser role on that DC.
- BZ - 998520 - [engine-config] /var/log/ovirt-engine/engine-config.log doesn't exist
- BZ - 998523 - RHEVM slow due to stored procedure getdisksvmguid() consuming most CPU
- BZ - 998539 - host with no unique id can be activated
- BZ - 999060 - [user portal] RHEVM slow due to stored procedure getdisksvmguid() consuming most CPU
- BZ - 999224 - [upgrade] correctly detect if packages can be rollbacked
CVEs
References
- https://access.redhat.com/security/updates/classification/#moderate
- https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Virtualization/3.2/html/Installation_Guide/Upgrading_between_Minor_Releases.html
- https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Virtualization/3.2/html/Technical_Notes/chap-RHSA-2013-1210.html
Red Hat Virtualization 3.2
SRPM | |
---|---|
x86_64 | |
rhevm-3.2.3-0.42.el6ev.noarch.rpm | SHA-256: 4c2a0c287283a7f0c8b60ee1ccddaf839266df32595f17f14b7d43015b9dc92b |
rhevm-backend-3.2.3-0.42.el6ev.noarch.rpm | SHA-256: e15bc2649c3467926106c127ba91c4bf2cca19517feee9210287af1c5c8e2610 |
rhevm-config-3.2.3-0.42.el6ev.noarch.rpm | SHA-256: 0b03dd78e9403ef54a583be176d10134a8d3b811f3e0066c976042d7c644f103 |
rhevm-dbscripts-3.2.3-0.42.el6ev.noarch.rpm | SHA-256: 998b114f5f4a732de2edd4b7a99735cbc09fca5a8db9dcd1d9cdac17820a4464 |
rhevm-genericapi-3.2.3-0.42.el6ev.noarch.rpm | SHA-256: 8f488594201ccb1aa34024178c912ef3156826a3091d0a945707330cee78a015 |
rhevm-notification-service-3.2.3-0.42.el6ev.noarch.rpm | SHA-256: a4031be3e60e1e0c9e824fc21fa1d14d4efdbfcc97f8c1114fcfbedb6a726724 |
rhevm-restapi-3.2.3-0.42.el6ev.noarch.rpm | SHA-256: dbde157f7f9cc38d6ab4ed94bea85dc0be3ea567f844a7ccea9df827809c57a3 |
rhevm-setup-3.2.3-0.42.el6ev.noarch.rpm | SHA-256: 23579c8e598f4ca8b57c85388e2b4d2d96e95e92f4b82b4ab14eed1d6ae13aa9 |
rhevm-setup-plugin-allinone-3.2.3-0.42.el6ev.noarch.rpm | SHA-256: 3ec7c11171508da271dd6c40b1139b4d83051bcab4a60dd4031bf11d3bdbe032 |
rhevm-tools-common-3.2.3-0.42.el6ev.noarch.rpm | SHA-256: 720c956cbb8234eb335f0a575510b272449c3df1985266101fe910285e1c6cf6 |
rhevm-userportal-3.2.3-0.42.el6ev.noarch.rpm | SHA-256: 6d12b941b19bd1edb2e65ad5ae28e0932235f4f7a2f5243ad18f1575c3d4bf4a |
rhevm-webadmin-portal-3.2.3-0.42.el6ev.noarch.rpm | SHA-256: 6f21fad0bcb4058846c133156ffe30d89bb1539faf553fb80a8af080c6beaf5c |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.