RHEL 6 : rhev-hypervisor6 (RHSA-2014:0979)

This script is Copyright (C) 2014-2017 Tenable Network Security, Inc.


Synopsis :

The remote Red Hat host is missing a security update.

Description :

An updated rhev-hypervisor6 package that fixes one security issue is
now available.

The Red Hat Security Response Team has rated this update as having
Moderate security impact. A Common Vulnerability Scoring System (CVSS)
base score, which gives a detailed severity rating, is available from
the CVE link in the References section.

The rhev-hypervisor6 package provides a Red Hat Enterprise
Virtualization Hypervisor ISO disk image. The Red Hat Enterprise
Virtualization Hypervisor is a dedicated Kernel-based Virtual Machine
(KVM) hypervisor. It includes everything necessary to run and manage
virtual machines: a subset of the Red Hat Enterprise Linux operating
environment and the Red Hat Enterprise Virtualization Agent.

Note: Red Hat Enterprise Virtualization Hypervisor is only available
for the Intel 64 and AMD64 architectures with virtualization
extensions.

It was found that NSS accepted weak Diffie-Hellman Key exchange (DHKE)
parameters. This could possibly lead to weak encryption being used in
communication between the client and the server. (CVE-2014-1491)

Red Hat would like to thank the Mozilla project for reporting the
CVE-2014-1491 issue. Upstream acknowledges Antoine Delignat-Lavaud and
Karthikeyan Bhargavan as the original reporters of CVE-2014-1491.

This update includes changes to the rhev-hypervisor component :

* The most recent build of rhev-hypervisor is included in version
3.4.1. (BZ#1118298)

This updated package also provides updated components that include
fixes for various security issues. These issues have no security
impact on Red Hat Enterprise Virtualization Hypervisor itself,
however. The security fixes included in this update address the
following CVE numbers :

CVE-2014-4699 and CVE-2014-4943 (kernel issues)

CVE-2014-4607 (lzo issue)

CVE-2013-1740, CVE-2014-1490, CVE-2014-1492, CVE-2014-1545, and
CVE-2014-1544 (nss and nspr issues)

Users of the Red Hat Enterprise Virtualization Hypervisor are advised
to upgrade to this updated package.

See also :

https://www.redhat.com/security/data/cve/CVE-2014-1491.html
http://www.nessus.org/u?64c6b598
http://rhn.redhat.com/errata/RHSA-2014-0979.html
http://www.nessus.org/u?c6b506c4

Solution :

Update the affected rhev-hypervisor6 package.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS Temporal Score : 3.9
(CVSS2#E:POC/RL:OF/RC:ND)
Public Exploit Available : true

Family: Red Hat Local Security Checks

Nessus Plugin ID: 79038 ()

Bugtraq ID: 65332

CVE ID: CVE-2014-1491

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now