CVE-2008-5714
published 2008-12-24CVE-2008-5714: Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCCINAN
EPSS
2.11%
79.9th percentile
Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 0.9.1-10 (bookworm) | qemu 0.9.1-10 (bookworm) |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 0.9.1-10 | 0.9.1-10 |
| qemu | qemu | >= 0 < 0.9.1-10 | 0.9.1-10 |
| qemu | qemu | >= 0 < 0.9.1-10 | 0.9.1-10 |
| qemu | qemu | >= 0 < 0.9.1-10 | 0.9.1-10 |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w8j8-f63m-pcx8: Off-by-one error in monitor
ghsa_unreviewed·2022-05-17
CVE-2008-5714 [HIGH] GHSA-w8j8-f63m-pcx8: Off-by-one error in monitor
Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended.
OSV
CVE-2008-5714: Off-by-one error in monitor
osv·2008-12-24·CVSS 7.8
CVE-2008-5714 [HIGH] CVE-2008-5714: Off-by-one error in monitor
Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended.
Ubuntu
KVM regression
vendor_ubuntu·2009-05-13·CVSS 2.1
[LOW] KVM regression
Title: KVM regression
Summary: KVM regression
USN-776-1 fixed vulnerabilities in KVM. Due to an incorrect fix, a
regression was introduced in Ubuntu 8.04 LTS that caused KVM to fail to
boot virtual machines started via libvirt. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Avi Kivity discovered that KVM did not correctly handle certain disk
formats. A local attacker could attach a malicious partition that would
allow the guest VM to read files on the VM host. (CVE-2008-1945,
CVE-2008-2004)
Alfredo Ortega discovered that KVM's VNC protocol handler did not
correctly validate certain messages. A remote attacker could send
specially crafted VNC messages that would cause KVM to consume CPU
resources, leading to a denial of service. (CVE-2008-
Ubuntu
KVM vulnerabilities
vendor_ubuntu·2009-05-12·CVSS 2.1
CVE-2008-1945 [LOW] KVM vulnerabilities
Title: KVM vulnerabilities
Summary: KVM vulnerabilities
Avi Kivity discovered that KVM did not correctly handle certain disk
formats. A local attacker could attach a malicious partition that
would allow the guest VM to read files on the VM host. (CVE-2008-1945,
CVE-2008-2004)
Alfredo Ortega discovered that KVM's VNC protocol handler did not
correctly validate certain messages. A remote attacker could send
specially crafted VNC messages that would cause KVM to consume CPU
resources, leading to a denial of service. (CVE-2008-2382)
Jan Niehusmann discovered that KVM's Cirrus VGA implementation over VNC
did not correctly handle certain bitblt operations. A local attacker
could exploit this flaw to potentially execute arbitrary code on the VM
host or crash KVM, leading to a denial of servic
Red Hat
qemu: off-by-one error in monitor.c causing VNC passwords to be truncated after 7th character
vendor_redhat·2008-11-23·CVSS 7.8
CVE-2008-5714 [HIGH] CWE-193 qemu: off-by-one error in monitor.c causing VNC passwords to be truncated after 7th character
qemu: off-by-one error in monitor.c causing VNC passwords to be truncated after 7th character
Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended.
Statement: Not vulnerable. This issue did not affect the versions of Xen as shipped with Red Hat Enterprise Linux 5.
Debian
CVE-2008-5714: qemu - Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote atta...
vendor_debian·2008·CVSS 7.8
CVE-2008-5714 [HIGH] CVE-2008-5714: qemu - Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote atta...
Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended.
Scope: local
bookworm: resolved (fixed in 0.9.1-10)
bullseye: resolved (fixed in 0.9.1-10)
forky: resolved (fixed in 0.9.1-10)
sid: resolved (fixed in 0.9.1-10)
trixie: resolved (fixed in 0.9.1-10)
No detection rules found.
No public exploits indexed.
http://lists.gnu.org/archive/html/qemu-devel/2008-11/msg01224.htmlhttp://lists.gnu.org/archive/html/qemu-devel/2008-12/msg00498.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.htmlhttp://secunia.com/advisories/33568http://secunia.com/advisories/34642http://secunia.com/advisories/35062http://svn.savannah.gnu.org/viewvc/?view=rev&root=qemu&revision=5966http://svn.savannah.gnu.org/viewvc/trunk/monitor.c?root=qemu&r1=5966&r2=5965&pathrev=5966http://www.securityfocus.com/bid/33020http://www.ubuntu.com/usn/usn-776-1https://exchange.xforce.ibmcloud.com/vulnerabilities/47683http://lists.gnu.org/archive/html/qemu-devel/2008-11/msg01224.htmlhttp://lists.gnu.org/archive/html/qemu-devel/2008-12/msg00498.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.htmlhttp://secunia.com/advisories/33568http://secunia.com/advisories/34642http://secunia.com/advisories/35062http://svn.savannah.gnu.org/viewvc/?view=rev&root=qemu&revision=5966http://svn.savannah.gnu.org/viewvc/trunk/monitor.c?root=qemu&r1=5966&r2=5965&pathrev=5966http://www.securityfocus.com/bid/33020http://www.ubuntu.com/usn/usn-776-1https://exchange.xforce.ibmcloud.com/vulnerabilities/47683
2008-12-24
Published