SB2017062021 - Red Hat update for Red Hat OpenStack Platform director



SB2017062021 - Red Hat update for Red Hat OpenStack Platform director

Published: June 20, 2017

Security Bulletin ID SB2017062021
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Authentication bypass (CVE-ID: CVE-2017-2637)

The vulnerability allows a remote unauthenticated attacker to bypass authentication on a targeted system.

The weakness exists due to the improper authentication and encryption standards that are set by default when the libvirtd component is deployed by the affected software. A remote attacker create a TCP connection to a compute host IP address, gain unauthorized access to the system that may allow to gain control of the host.

Successful exploitation of the vulnerability results in unauthorized access to the system.

Remediation

Install update from vendor's website.