CVE-2011-0011: Medium severity qemu vulnerability
Published Jan 25, 2011
·Updated
qemu-kvm before 0.11.0 disables VNC authentication when the password is cleared, which allows remote attackers to bypass authentication and establish VNC sessions.
Affected Software
19 affected components
debian/kvm
debian/qemu-kvm
Qemu Qemu<=0.11.0
Qemu Qemu=0.1.0
Qemu Qemu=0.1.1
Qemu Qemu=0.1.2
Qemu Qemu=0.1.3
Qemu Qemu=0.1.4
Qemu Qemu=0.1.5
Qemu Qemu=0.1.6
Qemu Qemu=0.10.0
Qemu Qemu=0.10.1
Qemu Qemu=0.10.2
Qemu Qemu=0.10.3
Qemu Qemu=0.10.4
Qemu Qemu=0.10.5
Qemu Qemu=0.10.6
Qemu Qemu=0.11.0-rc0
Qemu Qemu=0.11.0-rc1
Event History
Jan 25, 2011
Data Sourced
09:27 PM
SeverityAffected Software
Jun 21, 2012
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0011?
CVE-2011-0011 is considered to have a medium severity level due to its potential to allow unauthorized remote access through VNC.
2
How do I fix CVE-2011-0011?
To fix CVE-2011-0011, update to qemu-kvm version 0.11.0 or later, which addresses the vulnerability.
3
Which versions of qemu-kvm are affected by CVE-2011-0011?
Versions of qemu-kvm prior to 0.11.0 are affected by CVE-2011-0011.
4
What type of attacks can be executed due to CVE-2011-0011?
CVE-2011-0011 allows remote attackers to bypass VNC authentication and establish unauthorized VNC sessions.
5
Is VNC authentication affected by CVE-2011-0011?
Yes, CVE-2011-0011 disables VNC authentication when the password is cleared, leading to potential exploitation.