CVE-2008-5714Off-by-one Error in Qemu

Severity
7.8HIGHNVD
EPSS
0.7%
top 26.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 24
Latest updateMay 17

Description

Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended.

CVSS vector

AV:N/AC:L/C:C/I:N/A:NExploitability: 10.0 | Impact: 6.9

Affected Packages3 packages

debiandebian/qemu< qemu 0.9.1-10 (bookworm)
Debianqemu/qemu< 0.9.1-10+3
NVDqemu/qemu0.9.1

🔴Vulnerability Details

2
GHSA
GHSA-w8j8-f63m-pcx8: Off-by-one error in monitor2022-05-17
OSV
CVE-2008-5714: Off-by-one error in monitor2008-12-24

📋Vendor Advisories

4
Ubuntu
KVM regression2009-05-13
Ubuntu
KVM vulnerabilities2009-05-12
Red Hat
qemu: off-by-one error in monitor.c causing VNC passwords to be truncated after 7th character2008-11-23
Debian
CVE-2008-5714: qemu - Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote atta...2008

💬Community

1
Bugzilla
CVE-2008-5714 qemu: off-by-one error in monitor.c causing VNC passwords to be truncated after 7th character2009-01-23