Launchpad has imported 5 comments from the remote bug at
https://bugzilla.redhat.com/show_bug.cgi?id=668589.

If you reply to an imported comment from within Launchpad, your comment
will be sent to the remote bug automatically. Read more about
Launchpad's inter-bugtracker facilities at
https://help.launchpad.net/InterBugTracking.

------------------------------------------------------------------------
On 2011-01-10T20:45:01+00:00 Petr wrote:

Description of problem:
The semantics of the ',password' option to -vnc are that it enables the VNC 
auth scheme. If the VNC server password is unset or empty string, all attempts 
to authenticate with the server will be explicitly blocked.

This allows applications to enable and selectively allow access for a
period of time, before clearing the password again to prevent further
access.

Upstream changes have introduced a flaw by disabling all authentication
when the password was cleared with upstream commit [1].

[1]
http://www.qemu.com/qemu.git/commit/?id=52c18be9e99dabe295321153fda7fce9f76647ac

Reply at:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/697197/comments/9

------------------------------------------------------------------------
On 2011-01-28T18:02:42+00:00 Neil wrote:

Created attachment 475841
Fix to vnc password semantics

This patch corrects the flaw in qemu-kvm

Please see http://launchpad.net/bugs/697197 for testing performed.

Reply at:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/697197/comments/15

------------------------------------------------------------------------
On 2011-02-28T11:09:05+00:00 Petr wrote:

Created qemu tracking bugs for this issue

Affects: fedora-all [bug 680886]

Reply at:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/697197/comments/31

------------------------------------------------------------------------
On 2011-03-10T20:11:32+00:00 errata-xmlrpc wrote:

This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2011:0345 https://rhn.redhat.com/errata/RHSA-2011-0345.html

Reply at:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/697197/comments/32

------------------------------------------------------------------------
On 2012-03-30T17:33:58+00:00 Petr wrote:

Statement:

This issue does not affect versions of kvm package as shipped with Red
Hat Enterprise Linux 5.

Reply at:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/697197/comments/33

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/697197

Title:
  Empty password allows access to VNC in libvirt

To manage notifications about this bug go to:
https://bugs.launchpad.net/libvirt/+bug/697197/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to