CVE-2016-5008

Priority
Low
Description
libvirt before 2.0.0 improperly disables password checking when the
password on a VNC server is set to an empty string, which allows remote
attackers to bypass authentication and establish a VNC session by
connecting to the server.
References
Notes
 mdeslaur> vnc password authentication isn't strong and isn't recommended
 mdeslaur> so setting priority to low to bundle with another update
 leosilva> this CVE was original patched in unstable 2.0.0-1.
Assigned-to
mdeslaur
Package
Upstream:released (2.0.0-1)
Ubuntu 12.04 ESM (Precise Pangolin):needed
Ubuntu 14.04 LTS (Trusty Tahr):released (1.2.2-0ubuntu13.1.26)
Ubuntu 16.04 LTS (Xenial Xerus):released (1.3.1-1ubuntu10.19)
Ubuntu 17.10 (Artful Aardvark):released (2.1.0-1ubuntu1)
Ubuntu 18.04 LTS (Bionic Beaver):released (2.1.0-1.ubuntu1)
Ubuntu 18.10 (Cosmic Cuttlefish):released (2.1.0-1.ubuntu1)
Patches:
Upstream:http://libvirt.org/git/?p=libvirt.git;a=commit;h=bb848feec0f3f10e92dd8e5231ae7aa89b5598f3
More Information

Updated: 2018-06-26 04:07:53 UTC (commit 7799c934cca373482531a7b00e4dfe82302ceae5)