[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3613-1 libvirt -- libvirt

ID: oval:org.secpod.oval:def:602554Date: (C)2016-07-06   (M)2023-12-20
Class: PATCHFamily: unix




Vivian Zhang and Christoph Anton Mitterer discovered that setting an empty VNC password does not work as documented in Libvirt, a virtualisation abstraction library. When the password on a VNC server is set to the empty string, authentication on the VNC server will be disabled, allowing any user to connect, despite the documentation declaring that setting an empty password for the VNC server prevents all client connections. With this update the behaviour is enforced by setting the password expiration to "now".

Platform:
Debian 8.x
Product:
libvirt0
Reference:
DSA-3613-1
CVE-2016-5008
CVE    1
CVE-2016-5008
CPE    2
cpe:/o:debian:debian_linux:8.x
cpe:/a:redhat:libvirt:0

© SecPod Technologies