CVE-2015-0236Sensitive Information Exposure in Redhat Libvirt

Severity
3.5LOWNVD
EPSS
0.7%
top 29.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 29
Latest updateMay 14

Description

libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages7 packages

Also affects: Ubuntu Linux 12.04, 14.04, 15.04, 15.10

Patches

🔴Vulnerability Details

4
GHSA
GHSA-rj3c-3mq3-fpc6: libvirt before 12022-05-14
OSV
libvirt vulnerabilities2016-01-12
CVEList
CVE-2015-0236: libvirt before 12015-01-29
OSV
CVE-2015-0236: libvirt before 12015-01-29

📋Vendor Advisories

3
Ubuntu
libvirt vulnerabilities2016-01-12
Red Hat
libvirt: missing ACL check for the VIR_DOMAIN_XML_SECURE flag in save images and snapshots objects2015-01-22
Debian
CVE-2015-0236: libvirt - libvirt before 1.2.12 allow remote authenticated users to obtain the VNC passwor...2015

💬Community

2
Bugzilla
CVE-2015-0236 libvirt: missing ACL check for the VIR_DOMAIN_XML_SECURE flag in save images and snapshots objects [fedora-all]2015-01-26
Bugzilla
CVE-2015-0236 libvirt: missing ACL check for the VIR_DOMAIN_XML_SECURE flag in save images and snapshots objects2015-01-21
CVE-2015-0236 — Sensitive Information Exposure | cvebase