Security Advisory

CVE-2015-0236

3.5

Vulnerability Description

libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.
Published Date January 29, 2015
Official Source NIST NVD Advisory