Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
libvirt 信息泄露漏洞
Vulnerability Description
Red Hat libvirt是美国红帽(Red Hat)公司的一个用于实现Linux虚拟化功能的Linux API,它支持各种Hypervisor,包括Xen和KVM,以及QEMU和用于其他操作系统的一些虚拟产品。 libvirt 1.2.12之前版本中存在信息泄露漏洞,该漏洞源于没有充分过滤VIR_DOMAIN_XML_SECURE标志。远程攻击者可借助特制的快照或镜像利用该漏洞获取VNC密码。
CVSS Information
N/A
Vulnerability Type
N/A