cbcvebase.
CVE-2016-5008
published 2016-07-13

CVE-2016-5008: libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibvirt< libvirt 2.0.0-1 (bookworm)libvirt 2.0.0-1 (bookworm)
redhatlibvirt<= 1.3.5
redhatlibvirt>= 0 < 2.0.0-12.0.0-1
redhatlibvirt>= 0 < 2.0.0-12.0.0-1
redhatlibvirt>= 0 < 2.0.0-12.0.0-1
redhatlibvirt>= 0 < 2.0.0-12.0.0-1
redhatlibvirt>= 0 < 1.2.2-0ubuntu13.1.261.2.2-0ubuntu13.1.26
redhatlibvirt>= 0 < 1.3.1-1ubuntu10.191.3.1-1ubuntu10.19

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL