CVE-2015-0236: Infoleak
Published Jan 29, 2015
·Updated
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIRDOMAINXMLSECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.
Affected Software
23 affected components
Mageia Mageia=4.0
redhat libvirt<=1.2.11
redhat libvirt=1.2.0
redhat libvirt=1.2.1
redhat libvirt=1.2.2
redhat libvirt=1.2.3
redhat libvirt=1.2.4
redhat libvirt=1.2.5
redhat libvirt=1.2.6
redhat libvirt=1.2.7
redhat libvirt=1.2.8
redhat libvirt=1.2.9
redhat libvirt=1.2.10
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.04
Canonical Ubuntu Linux=15.10
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Hpc Node=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Workstation=7.0
Remediation
Patch Available
Event History
Jan 29, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0236?
CVE-2015-0236 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2015-0236?
To fix CVE-2015-0236, you should upgrade to libvirt version 1.2.12 or later.
3
What software versions are affected by CVE-2015-0236?
CVE-2015-0236 affects libvirt versions prior to 1.2.12 and specific Mageia and Ubuntu versions.
4
Can CVE-2015-0236 be exploited remotely?
Yes, CVE-2015-0236 can be exploited by remote authenticated users.
5
What type of information can be exposed due to CVE-2015-0236?
CVE-2015-0236 allows attackers to obtain the VNC password from the vulnerable systems.