CVE-2016-5008

Priority
Description
libvirt before 2.0.0 improperly disables password checking when the
password on a VNC server is set to an empty string, which allows remote
attackers to bypass authentication and establish a VNC session by
connecting to the server.
Assigned-to
mdeslaur
Notes
mdeslaurvnc password authentication isn't strong and isn't recommended
so setting priority to low to bundle with another update
leosilvathis CVE was original patched in unstable 2.0.0-1.
Package
Upstream:released (2.0.0-1)
Ubuntu 12.04 ESM (Precise Pangolin):needed
Ubuntu 14.04 ESM (Trusty Tahr):released (1.2.2-0ubuntu13.1.26)
Ubuntu 16.04 LTS (Xenial Xerus):released (1.3.1-1ubuntu10.19)
Ubuntu 18.04 LTS (Bionic Beaver):released (2.1.0-1.ubuntu1)
Ubuntu 19.04 (Disco Dingo):released (2.1.0-1.ubuntu1)
Ubuntu 19.10 (Eoan):released (2.1.0-1.ubuntu1)
Patches:
Upstream:http://libvirt.org/git/?p=libvirt.git;a=commit;h=bb848feec0f3f10e92dd8e5231ae7aa89b5598f3
More Information

Updated: 2019-10-18 02:27:07 UTC (commit cccfc4426d8c1fbf582a89d981fe7fc812124543)