CVE-2015-0236 PUBLISHED

libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.

EPSS 0.65% · 70.7th percentile

Risk Scores

EPSS Score
0.65%
70.7th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlibvirt0, 1.1.1-0ubuntu8, 1.1.1-0ubuntu9

Timeline

References

Open in Interactive Console →