CVE-2014-7823: Medium severity red hat libvirt-daemon-driver-storage-iscsi-direct vulnerability
Published Nov 13, 2014
·Updated
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIRDOMAINXMLMIGRATABLE flag, which triggers the use of the VIRDOMAINXMLSECURE flag.
Affected Software
11 affected components
redhat libvirt<=1.2.10
redhat libvirt=1.2.0
redhat libvirt=1.2.1
redhat libvirt=1.2.2
redhat libvirt=1.2.3
redhat libvirt=1.2.4
redhat libvirt=1.2.5
redhat libvirt=1.2.6
redhat libvirt=1.2.7
redhat libvirt=1.2.8
redhat libvirt=1.2.9
Remediation
Patch Available
Event History
Nov 13, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7823?
CVE-2014-7823 is considered a moderate severity vulnerability.
2
How do I fix CVE-2014-7823?
To fix CVE-2014-7823, upgrade Libvirt to version 1.2.11 or later.
3
Who is affected by CVE-2014-7823?
CVE-2014-7823 affects users running Libvirt versions before 1.2.11.
4
What does CVE-2014-7823 exploit?
CVE-2014-7823 exploits the virDomainGetXMLDesc API to leak the VNC password.
5
Can CVE-2014-7823 be mitigated without updating?
Mitigation of CVE-2014-7823 without updating is challenging, but limiting user permissions may help.