Security Advisory
CVE-2015-0236
3.5
Vulnerability Description
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.
Published Date
January 29, 2015
Official Source
NIST NVD Advisory