libvirt before 1.2.12 allow remote authenticated users to obtain the...
Vulnerability Description
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-0236
Credits & Attribution
No credits recorded in the NVD database.
References
- http://security.libvirt.org/2015/0001.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:070
- http://advisories.mageia.org/MGASA-2015-0046.html
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00028.html
- http://secunia.com/advisories/62766
- http://rhn.redhat.com/errata/RHSA-2015-0323.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:035
- http://www.ubuntu.com/usn/USN-2867-1
More from mageia
View All →Affected Vendor
mageia
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.