CVE-2014-7823
13.11.2014, 21:32
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | libvirt | 𝑥 ≤ 1.2.10 |
redhat | libvirt | 1.2.0 |
redhat | libvirt | 1.2.1 |
redhat | libvirt | 1.2.2 |
redhat | libvirt | 1.2.3 |
redhat | libvirt | 1.2.4 |
redhat | libvirt | 1.2.5 |
redhat | libvirt | 1.2.6 |
redhat | libvirt | 1.2.7 |
redhat | libvirt | 1.2.8 |
redhat | libvirt | 1.2.9 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References