Description
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
Exploits
No known exploits found for this CVE.
Search Exploit-DBReferences
secalert@redhat.com
http://lists.opensuse.org/opensuse-updates/2014-11/msg00083.htmlsecalert@redhat.com
http://secunia.com/advisories/60010secalert@redhat.com
http://secunia.com/advisories/60895secalert@redhat.com
http://secunia.com/advisories/62058secalert@redhat.com
http://secunia.com/advisories/62303secalert@redhat.com
http://security.gentoo.org/glsa/glsa-201412-04.xmlsecalert@redhat.com
http://security.libvirt.org/2014/0007.htmlsecalert@redhat.com
http://www.ubuntu.com/usn/USN-2404-1af854a3a-2127-422b-91ae-364da2661108
http://lists.opensuse.org/opensuse-updates/2014-11/msg00083.htmlaf854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/60010af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/60895af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/62058af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/62303af854a3a-2127-422b-91ae-364da2661108
http://security.gentoo.org/glsa/glsa-201412-04.xmlaf854a3a-2127-422b-91ae-364da2661108
http://security.libvirt.org/2014/0007.htmlaf854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/USN-2404-1