CVE Vulnerabilities

CVE-2014-7823

Published: Nov 13, 2014 | Modified: Jan 03, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
3.3 LOW
AV:A/AC:L/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.

Affected Software

Name Vendor Start Version End Version
Libvirt Redhat * 1.2.10 (including)
Libvirt Redhat 1.2.0 (including) 1.2.0 (including)
Libvirt Redhat 1.2.1 (including) 1.2.1 (including)
Libvirt Redhat 1.2.2 (including) 1.2.2 (including)
Libvirt Redhat 1.2.3 (including) 1.2.3 (including)
Libvirt Redhat 1.2.4 (including) 1.2.4 (including)
Libvirt Redhat 1.2.5 (including) 1.2.5 (including)
Libvirt Redhat 1.2.6 (including) 1.2.6 (including)
Libvirt Redhat 1.2.7 (including) 1.2.7 (including)
Libvirt Redhat 1.2.8 (including) 1.2.8 (including)
Libvirt Redhat 1.2.9 (including) 1.2.9 (including)
Red Hat Enterprise Linux 6 RedHat libvirt-0:0.10.2-46.el6_6.2 *
Red Hat Enterprise Linux 7 RedHat libvirt-0:1.1.1-29.el7_0.4 *
Libvirt Ubuntu devel *
Libvirt Ubuntu trusty *
Libvirt Ubuntu utopic *

References