Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5008

Опубликовано: 18 янв. 2015
Источник: redhat
CVSS3: 5.6
CVSS2: 5.1

Описание

libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.

It was found that setting a VNC password to an empty string in libvirt did not disable all access to the VNC server as documented, instead it allowed access with no authentication required. An attacker could use this flaw to access a VNC server with an empty VNC password without any authentication.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libvirtNot affected
Red Hat Enterprise Linux 6libvirtWill not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerUnder investigation
Red Hat Enterprise Linux 7libvirtFixedRHSA-2016:257703.11.2016
Red Hat Gluster Storage 3.1 for RHEL 7libvirtFixedRHSA-2016:257703.11.2016
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7libvirtFixedRHSA-2016:257703.11.2016

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1351514libvirt: Setting empty VNC password allows access to unauthorized users

5.6 Medium

CVSS3

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.

CVSS3: 9.8
nvd
около 9 лет назад

libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.

CVSS3: 9.8
debian
около 9 лет назад

libvirt before 2.0.0 improperly disables password checking when the pa ...

suse-cvrf
около 9 лет назад

Security update for libvirt

suse-cvrf
около 9 лет назад

Security update for libvirt

5.6 Medium

CVSS3

5.1 Medium

CVSS2