CVE-2010-2223
published 2010-06-24CVE-2010-2223: Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.37%
29.6th percentile
Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a virtual machine's data, which allows guest OS users to obtain sensitive information by examining the disk blocks associated with a deleted virtual machine.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_virtualization_hypervisor | <= 5.4-2.1 | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
vdsm: missing VM post-zeroing after removal
vendor_redhat·2009-10-22·CVSS 2.1
CVE-2010-2223 [LOW] vdsm: missing VM post-zeroing after removal
vdsm: missing VM post-zeroing after removal
Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a virtual machine's data, which allows guest OS users to obtain sensitive information by examining the disk blocks associated with a deleted virtual machine.
Previously, the ISO image domain could not be shared with multiple Data Centers. The user had to define an independent ISO domain for each Data Center. With this update, the ISO image domain can be shared between multiple Data Centers.
GHSA
GHSA-q8g8-jjw3-wwpx: Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5
ghsa_unreviewed·2022-05-17
CVE-2010-2223 [LOW] GHSA-q8g8-jjw3-wwpx: Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5
Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a virtual machine's data, which allows guest OS users to obtain sensitive information by examining the disk blocks associated with a deleted virtual machine.
No detection rules found.
No public exploits indexed.
http://securitytracker.com/id?1024137http://www.securityfocus.com/bid/41044https://bugzilla.redhat.com/show_bug.cgi?id=604752https://rhn.redhat.com/errata/RHSA-2010-0473.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0476.htmlhttp://securitytracker.com/id?1024137http://www.securityfocus.com/bid/41044https://bugzilla.redhat.com/show_bug.cgi?id=604752https://rhn.redhat.com/errata/RHSA-2010-0473.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0476.html
2010-06-24
Published