Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Qemu | Qemu | 0.9.1 (including) | 0.9.1 (including) |
| Kvm | Ubuntu | gutsy | * |
| Kvm | Ubuntu | hardy | * |
| Kvm | Ubuntu | intrepid | * |
| Qemu | Ubuntu | dapper | * |
| Qemu | Ubuntu | gutsy | * |
| Qemu | Ubuntu | hardy | * |
| Qemu | Ubuntu | intrepid | * |
| Qemu | Ubuntu | jaunty | * |
| Xen-3.1 | Ubuntu | gutsy | * |
| Xen-3.1 | Ubuntu | hardy | * |
| Xen-3.1 | Ubuntu | intrepid | * |
| Xen-3.2 | Ubuntu | hardy | * |
| Xen-3.3 | Ubuntu | intrepid | * |
| Xen-3.3 | Ubuntu | jaunty | * |
| Xen-3.3 | Ubuntu | karmic | * |
| Xen-3.3 | Ubuntu | lucid | * |
| Xen-3.3 | Ubuntu | maverick | * |
| Xen-3.3 | Ubuntu | natty | * |
| Xen-unstable | Ubuntu | gutsy | * |