This bug was fixed in the package qemu-kvm - 0.13.0+noroms-0ubuntu13 --------------- qemu-kvm (0.13.0+noroms-0ubuntu13) natty; urgency=low
[ Neil Wilson <n...@aldur.co.uk> ] * SECURITY UPDATE: Setting VNC password to empty string silently disables all authentication (LP: #697197) - debian/patches/697197-fix-vnc-password-semantics.patch: Reverses the change introduced in Qemu by git commit 52c18be9 - CVE: 2011-0011 [ Dustin Kirkland ] * Updated patch to reflect the move of vnc.c to ui/vnc.c -- Dustin Kirkland <kirkl...@ubuntu.com> Fri, 11 Feb 2011 09:53:19 -0600 ** Changed in: qemu-kvm (Ubuntu Natty) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libvirt in ubuntu. https://bugs.launchpad.net/bugs/697197 Title: Empty password allows access to VNC in libvirt -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs