CVE-2016-5008: Critical severity redhat libvirt vulnerability
Last updated 25 August 2025
Other sources
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2016-5008?
CVE-2016-5008 is a vulnerability in libvirt that allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.
What is the severity of CVE-2016-5008?
CVE-2016-5008 has a severity rating of 9.8, which is considered critical.
How does CVE-2016-5008 affect libvirt?
CVE-2016-5008 affects libvirt versions before 2.0.0.
How can I fix CVE-2016-5008?
To fix CVE-2016-5008, update libvirt to version 2.0.0 or later.
Where can I find more information about CVE-2016-5008?
More information about CVE-2016-5008 can be found at the following references: [link1](http://www.securityfocus.com/bid/91562), [link2](http://www.debian.org/security/2016/dsa-3613), [link3](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DZZMOMRXNPALA34XDF5NK363KDLAYSTL/)