Red Hat Bugzilla – Bug 668589
CVE-2011-0011 qemu-kvm: Setting VNC password to empty string silently disables all authentication
Last modified: 2015-07-29 09:39:46 EDT
Description of problem:
The semantics of the ',password' option to -vnc are that it enables the VNC auth scheme. If the VNC server password is unset or empty string, all attempts to authenticate with the server will be explicitly blocked.
This allows applications to enable and selectively allow access for a period of time, before clearing the password again to prevent further access.
Upstream changes have introduced a flaw by disabling all authentication when the password was cleared with upstream commit .
Created attachment 475841 [details]
Fix to vnc password semantics
This patch corrects the flaw in qemu-kvm
Please see http://launchpad.net/bugs/697197 for testing performed.
Created qemu tracking bugs for this issue
Affects: fedora-all [bug 680886]
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0345 https://rhn.redhat.com/errata/RHSA-2011-0345.html
This issue does not affect versions of kvm package as shipped with Red Hat Enterprise Linux 5.