7.8
CVSSv2

CVE-2008-5714

Published: 24/12/2008 Updated: 08/08/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote malicious users to guess the VNC password, which is limited to seven characters where eight was intended.

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu 0.9.1

Vendor Advisories

Debian Bug report logs - #509882 password limited to seven, not eight characters Package: qemu; Maintainer for qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Source for qemu is src:qemu (PTS, buildd, popcon) Reported by: Thijs Kinkhorst <thijs@debianorg> Date: Sat, 27 Dec 2008 12:33:01 UTC Sever ...
USN-776-1 fixed vulnerabilities in KVM Due to an incorrect fix, a regression was introduced in Ubuntu 804 LTS that caused KVM to fail to boot virtual machines started via libvirt This update fixes the problem We apologize for the inconvenience ...
Avi Kivity discovered that KVM did not correctly handle certain disk formats A local attacker could attach a malicious partition that would allow the guest VM to read files on the VM host (CVE-2008-1945, CVE-2008-2004) ...
Several vulnerabilities have been discovered in kvm, a full virtualization system The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-5714 Chris Webb discovered an off-by-one bug limiting KVM's VNC passwords to 7 characters This flaw might make it easier for remote attackers to guess the VNC password, whi ...