oss-sec mailing list archives

CVE request: qemu-kvm: Setting VNC password to empty string silently disables all authentication


From: Petr Matousek <pmatouse () redhat com>
Date: Mon, 10 Jan 2011 16:22:04 -0500 (EST)

"The semantics of the ',password' option to -vnc are that it enables the VNC
auth scheme. If the VNC server password is unset or empty string, all attempts
to authenticate with the server will be explicitly blocked.

This allows applications to enable and selectively allow access for a period of
time, before clearing the password again to prevent further access.

Upstream changes have introduced a flaw by disabling all authentication when
the password was cleared with upstream commit [1].

[1]
http://www.qemu.com/qemu.git/commit/?id=52c18be9e99dabe295321153fda7fce9f76647ac";

Reference:
https://bugzilla.redhat.com/show_bug.cgi?id=668589

Thanks,
--
Petr Matousek / Red Hat Security Response Team


Current thread: