Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-0011
HistoryFeb 11, 2011 - 12:00 a.m.

CVE-2011-0011

2011-02-1100:00:00
ubuntu.com
ubuntu.com
17

CVSS2

4.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:H/Au:N/C:P/I:P/A:P

EPSS

0.012

Percentile

85.2%

qemu-kvm before 0.11.0 disables VNC authentication when the password is
cleared, which allows remote attackers to bypass authentication and
establish VNC sessions.

Notes

Author Note
kees qemu in hardy and dapper were not affected
OSVersionArchitecturePackageVersionFilename
ubuntu9.10noarchqemu-kvm< 0.11.0-0ubuntu6.4UNKNOWN
ubuntu10.04noarchqemu-kvm< 0.12.3+noroms-0ubuntu9.4UNKNOWN
ubuntu10.10noarchqemu-kvm< 0.12.5+noroms-0ubuntu7.2UNKNOWN

CVSS2

4.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:H/Au:N/C:P/I:P/A:P

EPSS

0.012

Percentile

85.2%