Back

MEDIUM

libvirt: dumpxml: information leak with migratable flag

Published Nov 13, 2014

Description

The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.

Affected products

Remediation

Red Hat statement

This issue does not affect the versions of libvirt packages as shipped with Red Hat Enterprise Linux 5. This issue does affect the versions of libvirt packages as shipped with Red Hat Enterprise Linux 6 and 7. Future updates may address this issue in the respective Red Hat Enterprise Linux releases.

Metrics

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 13, 2014
Updated Aug 6, 2024
Reserved Oct 3, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 5, 2014