libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.
2015-01-29T15:59:00.060
2025-04-12T10:46:40.837
Deferred
CVSSv2: 3.5 (LOW)
AV:N/AC:M/Au:S/C:P/I:N/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | mageia | mageia | 4.0 | Yes |
Application | redhat | libvirt | ≤ 1.2.11 | Yes |
Application | redhat | libvirt | 1.2.0 | Yes |
Application | redhat | libvirt | 1.2.1 | Yes |
Application | redhat | libvirt | 1.2.2 | Yes |
Application | redhat | libvirt | 1.2.3 | Yes |
Application | redhat | libvirt | 1.2.4 | Yes |
Application | redhat | libvirt | 1.2.5 | Yes |
Application | redhat | libvirt | 1.2.6 | Yes |
Application | redhat | libvirt | 1.2.7 | Yes |
Application | redhat | libvirt | 1.2.8 | Yes |
Application | redhat | libvirt | 1.2.9 | Yes |
Application | redhat | libvirt | 1.2.10 | Yes |
Operating System | opensuse | opensuse | 13.1 | No |
Operating System | opensuse | opensuse | 13.2 | No |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 15.04 | Yes |
Operating System | canonical | ubuntu_linux | 15.10 | Yes |
Operating System | redhat | enterprise_linux_desktop | 7.0 | Yes |
Operating System | redhat | enterprise_linux_hpc_node | 7.0 | Yes |
Operating System | redhat | enterprise_linux_server | 7.0 | Yes |
Operating System | redhat | enterprise_linux_workstation | 7.0 | Yes |