ALT-PU-2015-1157-1
Closed vulnerabilities
Published: 2015-01-29
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2015-0236
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.
Severity: LOW (3.5)
References:
- http://advisories.mageia.org/MGASA-2015-0046.html
- http://advisories.mageia.org/MGASA-2015-0046.html
- openSUSE-SU-2015:0225
- openSUSE-SU-2015:0225
- RHSA-2015:0323
- RHSA-2015:0323
- 62766
- 62766
- http://security.libvirt.org/2015/0001.html
- http://security.libvirt.org/2015/0001.html
- MDVSA-2015:035
- MDVSA-2015:035
- MDVSA-2015:070
- MDVSA-2015:070
- USN-2867-1
- USN-2867-1