CVE-2015-0236
EPSS 0.49%Published: 1/29/2015Modified: 4/28/2026
Also known as:DEBIAN-CVE-2015-0236
Description
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.
Affected packages (1)
- Debian/libvirtfrom 0, < 1.2.9-8