Описание
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 1.2.8-0ubuntu14 |
| esm-infra-legacy/trusty | released | 1.2.2-0ubuntu13.1.7 |
| lucid | not-affected | 0.7.5-5ubuntu27.24 |
| precise | not-affected | 0.9.8-2ubuntu17.20 |
| trusty | released | 1.2.2-0ubuntu13.1.7 |
| trusty/esm | released | 1.2.2-0ubuntu13.1.7 |
| upstream | needs-triage | |
| utopic | released | 1.2.8-0ubuntu11.1 |
Показывать по
5 Medium
CVSS2
Связанные уязвимости
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote rea ...
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
ELSA-2015-0008: libvirt security and bug fix update (LOW)
5 Medium
CVSS2