CVE Vulnerabilities

CVE-2011-1773

Published: Feb 08, 2014 | Modified: Apr 22, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu

virt-v2v before 0.8.4 does not preserve the VNC console password when converting a guest, which allows local users to bypass the intended VNC authentication by connecting without a password.

Affected Software

Name Vendor Start Version End Version
Virt-v2v Matthew_booth * 0.8.3 (including)
Virt-v2v Matthew_booth 0.1.0 (including) 0.1.0 (including)
Virt-v2v Matthew_booth 0.2.0 (including) 0.2.0 (including)
Virt-v2v Matthew_booth 0.3.0 (including) 0.3.0 (including)
Virt-v2v Matthew_booth 0.3.2 (including) 0.3.2 (including)
Virt-v2v Matthew_booth 0.4.0 (including) 0.4.0 (including)
Virt-v2v Matthew_booth 0.4.9 (including) 0.4.9 (including)
Virt-v2v Matthew_booth 0.4.10 (including) 0.4.10 (including)
Virt-v2v Matthew_booth 0.5.0 (including) 0.5.0 (including)
Virt-v2v Matthew_booth 0.5.1 (including) 0.5.1 (including)
Virt-v2v Matthew_booth 0.5.2 (including) 0.5.2 (including)
Virt-v2v Matthew_booth 0.5.3 (including) 0.5.3 (including)
Virt-v2v Matthew_booth 0.5.4 (including) 0.5.4 (including)
Virt-v2v Matthew_booth 0.6.0 (including) 0.6.0 (including)
Virt-v2v Matthew_booth 0.6.1 (including) 0.6.1 (including)
Virt-v2v Matthew_booth 0.6.2 (including) 0.6.2 (including)
Virt-v2v Matthew_booth 0.6.3 (including) 0.6.3 (including)
Virt-v2v Matthew_booth 0.7.0 (including) 0.7.0 (including)
Virt-v2v Matthew_booth 0.7.1 (including) 0.7.1 (including)
Virt-v2v Matthew_booth 0.8.0 (including) 0.8.0 (including)
Virt-v2v Matthew_booth 0.8.1 (including) 0.8.1 (including)
Virt-v2v Matthew_booth 0.8.2 (including) 0.8.2 (including)
Red Hat Enterprise Linux 6 RedHat virt-v2v-0:0.8.3-5.el6 *

References