QEMU Password Option Error Lets Remote Users Bypass Authentication
|
|
SecurityTracker Alert ID: 1025199 |
|
SecurityTracker URL: http://securitytracker.com/id/1025199
|
|
CVE Reference:
CVE-2011-0011
(Links to External Site)
|
Date: Mar 11 2011
|
Impact:
Host/resource access via network
|
Exploit Included: Yes
|
Version(s): 0.11.0-rc2 - 0.14.0
|
Description:
A vulnerability was reported in QEMU. A remote user can bypass authentication in certain cases.
When a password is cleared via the VNC 'password' option, VNC authentication is disabled. A remote user that is able to connect to the VNC ports can open a VNC session without authentication.
|
Impact:
A remote user that is able to connect to the VNC ports can open a VNC session without authentication.
|
Solution:
No solution was available at the time of this entry.
|
Vendor URL: wiki.qemu.org/Main_Page (Links to External Site)
|
Cause:
Authentication error, State error
|
Underlying OS:
Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Fri, 11 Mar 2011 06:24:31 +0000
Subject: QEMU
|
http://www.qemu.com/qemu.git/commit/?id=52c18be9e99dabe295321153fda7fce9f76647ac
CVE-2011-0011
|
|