virt-v2v Disabled Target VNC Password Security Bypass Vulnerability
BID:47748
Info
virt-v2v Disabled Target VNC Password Security Bypass Vulnerability
| Bugtraq ID: | 47748 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | May 06 2011 12:00AM |
| Updated: | May 06 2011 12:00AM |
| Credit: | Petr Matousek |
| Vulnerable: |
virt-v2v virt-v2v 0.6.3 |
| Not Vulnerable: | |
Discussion
virt-v2v Disabled Target VNC Password Security Bypass Vulnerability
The 'virt-v2v' utility is prone to a security-bypass vulnerability.
Attackers can exploit this issue to operate the target virtual machine (VM) with the permissions of the currently logged in user. The target VM may be in an insecure state; users may have a false sense of security.
virt-v2v 0.6.3 is vulnerable; other versions may also be affected.
The 'virt-v2v' utility is prone to a security-bypass vulnerability.
Attackers can exploit this issue to operate the target virtual machine (VM) with the permissions of the currently logged in user. The target VM may be in an insecure state; users may have a false sense of security.
virt-v2v 0.6.3 is vulnerable; other versions may also be affected.
Exploit / POC
virt-v2v Disabled Target VNC Password Security Bypass Vulnerability
Attackers can exploit this issue with readily available tools.
Attackers can exploit this issue with readily available tools.
Solution / Fix
virt-v2v Disabled Target VNC Password Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
virt-v2v Disabled Target VNC Password Security Bypass Vulnerability
References:
References:
- Bug 702754 - virt-v2v: vnc password protection is missing after vm conversion (Petr Matousek)
- CVE request -- virt-v2v: vnc password protection is missing after vm conversion (Petr Matousek)
- virt-v2v Homepage (virt-v2v)