virt-v2v before 0.8.4 does not preserve the VNC console password when converting a guest, which allows local users to bypass the intended VNC authentication by connecting without a password.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2014-02-08 00:55
Updated : 2019-04-22 17:48
NVD link : CVE-2011-1773
Mitre link : CVE-2011-1773
CVE.ORG link : CVE-2011-1773
JSON object : View
Products Affected
redhat
- enterprise_linux
matthew_booth
- virt-v2v
CWE
CWE-255
Credentials Management Errors