CVE Vulnerabilities

CVE-2011-1773

Published: Feb 08, 2014 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

virt-v2v before 0.8.4 does not preserve the VNC console password when converting a guest, which allows local users to bypass the intended VNC authentication by connecting without a password.

Affected Software

NameVendorStart VersionEnd Version
Virt-v2vMatthew_booth*0.8.3 (including)
Virt-v2vMatthew_booth0.1.0 (including)0.1.0 (including)
Virt-v2vMatthew_booth0.2.0 (including)0.2.0 (including)
Virt-v2vMatthew_booth0.3.0 (including)0.3.0 (including)
Virt-v2vMatthew_booth0.3.2 (including)0.3.2 (including)
Virt-v2vMatthew_booth0.4.0 (including)0.4.0 (including)
Virt-v2vMatthew_booth0.4.9 (including)0.4.9 (including)
Virt-v2vMatthew_booth0.4.10 (including)0.4.10 (including)
Virt-v2vMatthew_booth0.5.0 (including)0.5.0 (including)
Virt-v2vMatthew_booth0.5.1 (including)0.5.1 (including)
Virt-v2vMatthew_booth0.5.2 (including)0.5.2 (including)
Virt-v2vMatthew_booth0.5.3 (including)0.5.3 (including)
Virt-v2vMatthew_booth0.5.4 (including)0.5.4 (including)
Virt-v2vMatthew_booth0.6.0 (including)0.6.0 (including)
Virt-v2vMatthew_booth0.6.1 (including)0.6.1 (including)
Virt-v2vMatthew_booth0.6.2 (including)0.6.2 (including)
Virt-v2vMatthew_booth0.6.3 (including)0.6.3 (including)
Virt-v2vMatthew_booth0.7.0 (including)0.7.0 (including)
Virt-v2vMatthew_booth0.7.1 (including)0.7.1 (including)
Virt-v2vMatthew_booth0.8.0 (including)0.8.0 (including)
Virt-v2vMatthew_booth0.8.1 (including)0.8.1 (including)
Virt-v2vMatthew_booth0.8.2 (including)0.8.2 (including)
Red Hat Enterprise Linux 6RedHatvirt-v2v-0:0.8.3-5.el6*

References