Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2014:1002 - Security Advisory
Issued:
2014-08-04
Updated:
2014-08-04

RHSA-2014:1002 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: rhevm security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Updated rhevm packages that fix one security issue are now available.

The Red Hat Security Response Team has rated this update as having Moderate
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.

Description

Red Hat Enterprise Virtualization is a feature-rich server virtualization
management system that provides advanced capabilities for managing Red Hat
virtualization infrastructure for Servers and Desktops.

It was found that the oVirt storage back end did not wipe memory snapshots
when VMs were deleted, even if wipe-after-delete (WAD) was enabled for the
VM's disks. A remote attacker with credentials to create a new VM could use
this flaw to potentially access the contents of memory snapshots in an
uninitialized storage volume, possibly leading to the disclosure of
sensitive information. (CVE-2014-3559)

This issue was discovered by Idan Shaby and Allon Mureinik of Red Hat.

All rhevm users are advised to upgrade to these updated packages, which
correct this issue.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to use the
Red Hat Network to apply this update are available at
https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Virtualization 3.4 x86_64

Fixes

  • BZ - 1121925 - CVE-2014-3559 ovirt-engine-backend: memory snapshots not wiped when deleting a VM with wipe-after-delete (WAD) enabled for its disks

CVEs

  • CVE-2014-3559

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Virtualization 3.4

SRPM
rhevm-3.4.1-0.31.el6ev.src.rpm SHA-256: 982af0dd0d3f8c1b78baec3dc94b175d23cd594be38a26c4ac96013fe2816ab3
x86_64
rhevm-3.4.1-0.31.el6ev.noarch.rpm SHA-256: ae57892d03c9050eeceb34eb81699d72af1fb1dda3b01bd075e0e9e960bde2c1
rhevm-backend-3.4.1-0.31.el6ev.noarch.rpm SHA-256: 5bb721b4bbceb174c7f6690b008efa8b8abf2a24142f07cebbb9b2c84c6734ec
rhevm-dbscripts-3.4.1-0.31.el6ev.noarch.rpm SHA-256: c536baac0551f4fa790cf5e58bce4b213c4175815c8a44c90b753306d7f780a1
rhevm-lib-3.4.1-0.31.el6ev.noarch.rpm SHA-256: 0604fe76d3590e2dad814e141eb6f53761090d7b246a7ca1dcc99dba7ce2f6fb
rhevm-restapi-3.4.1-0.31.el6ev.noarch.rpm SHA-256: e7a3c214f78bf139a349761289e1e3a3dd3986bb84326a6ded4f548987b52445
rhevm-setup-3.4.1-0.31.el6ev.noarch.rpm SHA-256: c0d90526370d6a793438a8887b88b77b59fc20b639ccfd552c607a0ad396f04a
rhevm-setup-base-3.4.1-0.31.el6ev.noarch.rpm SHA-256: 7e5861610778b33edc82977fbb2b4c71264feeed479407a03eaa0051dede835e
rhevm-setup-plugin-allinone-3.4.1-0.31.el6ev.noarch.rpm SHA-256: 6cfae990daec01a3db7d4164bb309690d0b9336bdbb243120a6abf2d5ce1550a
rhevm-setup-plugin-ovirt-engine-3.4.1-0.31.el6ev.noarch.rpm SHA-256: 171df0c7015ce373cc39a67e73f8d011ad39ea2d564f79737c6b4278a224edc7
rhevm-setup-plugin-ovirt-engine-common-3.4.1-0.31.el6ev.noarch.rpm SHA-256: 78adcdcae616a672db93592694aead5272d82ad7c7d169228402c650b5f0d37f
rhevm-setup-plugin-websocket-proxy-3.4.1-0.31.el6ev.noarch.rpm SHA-256: 570e23297b495406d3fae2821bc01b4e31de06100953a6c846a83e262680df4c
rhevm-tools-3.4.1-0.31.el6ev.noarch.rpm SHA-256: 11e4a5bd37fb18957a75648f4e02b6277d503aa6bb23d9617a402883aa47d629
rhevm-userportal-3.4.1-0.31.el6ev.noarch.rpm SHA-256: 90a26c814cd310d2ddc0c64c3a86cbac2c6c76caf83c3433e4c9b393acebc6cd
rhevm-webadmin-portal-3.4.1-0.31.el6ev.noarch.rpm SHA-256: 3c98c5fb0d23f00d90e37464011a7eb867892ea48c65daa927472266a7f978a8
rhevm-websocket-proxy-3.4.1-0.31.el6ev.noarch.rpm SHA-256: 242611e269a5df567ed99c1b9e045e6e8d429e83cb54b48440374a441753c859

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility