CVE Vulnerabilities

CVE-2014-7823

Published: Nov 13, 2014 | Modified: Jan 03, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.

Affected Software

Name Vendor Start Version End Version
Libvirt Redhat * 1.2.10 (including)
Libvirt Redhat 1.2.0 (including) 1.2.0 (including)
Libvirt Redhat 1.2.1 (including) 1.2.1 (including)
Libvirt Redhat 1.2.2 (including) 1.2.2 (including)
Libvirt Redhat 1.2.3 (including) 1.2.3 (including)
Libvirt Redhat 1.2.4 (including) 1.2.4 (including)
Libvirt Redhat 1.2.5 (including) 1.2.5 (including)
Libvirt Redhat 1.2.6 (including) 1.2.6 (including)
Libvirt Redhat 1.2.7 (including) 1.2.7 (including)
Libvirt Redhat 1.2.8 (including) 1.2.8 (including)
Libvirt Redhat 1.2.9 (including) 1.2.9 (including)

References