Back

MEDIUM

qemu-kvm: Setting VNC password to empty string silently disables all authentication

Published Jun 21, 2012

Description

qemu-kvm before 0.11.0 disables VNC authentication when the password is cleared, which allows remote attackers to bypass authentication and establish VNC sessions.

Affected products

Remediation

Red Hat statement

This issue does not affect versions of kvm package as shipped with Red Hat Enterprise Linux 5.

Metrics

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 21, 2012
Updated Aug 6, 2024
Reserved Dec 7, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Jan 7, 2011