virt-who uses world-readable permissions for /etc/sysconfig/virt-who, which allows local users to obtain password for hypervisors by reading the file.
https://bugzilla.redhat.com/show_bug.cgi?id=1088732
https://bugzilla.redhat.com/show_bug.cgi?id=1081286
http://www.securityfocus.com/bid/67089