[3.4] libvirt: Setting empty VNC password allows access to unauthorized users (CVE-2016-5008)ID: oval:org.secpod.oval:def:1800496 | Date: (C)2018-03-30 (M)2023-12-20 |
Class: PATCH | Family: unix |
It was found that setting VNC password to empty string doesn"t work in a way as it"s documented. The documented semantics of setting the password to an empty string are that it disables all access to the VNC server, however in fact it allows all users access with no authentication required instead.
Platform: |
Alpine Linux 3.4 |