[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.4] libvirt: Setting empty VNC password allows access to unauthorized users (CVE-2016-5008)

ID: oval:org.secpod.oval:def:1800496Date: (C)2018-03-30   (M)2023-12-20
Class: PATCHFamily: unix




It was found that setting VNC password to empty string doesn"t work in a way as it"s documented. The documented semantics of setting the password to an empty string are that it disables all access to the VNC server, however in fact it allows all users access with no authentication required instead.

Platform:
Alpine Linux 3.4
Product:
libvirt
Reference:
5875
CVE-2016-5008
CVE    1
CVE-2016-5008
CPE    2
cpe:/o:alpinelinux:alpine_linux:3.4
cpe:/a:redhat:libvirt

© SecPod Technologies