SB2016071919 - Improper Authentication in libvirt (Alpine package)
Published: July 19, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authentication (CVE-ID: CVE-2016-5008)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests. libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=0b2c0b7464ec1f08d031a6736dfd33bcb4dba7a1
- https://git.alpinelinux.org/aports/commit/?id=30dd31aad0b6aab5f2a186648375ed55de573b9f
- https://git.alpinelinux.org/aports/commit/?id=fe21e87ffd9382eed66543f8c2d0f740878849d7
- https://git.alpinelinux.org/aports/commit/?id=0506722e21955765f56dfc4b6f2af39ad6b1a338