Vulnerabilities > CVE-2011-1773 - Credentials Management vulnerability in multiple products

047910
CVSS 4.4 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

virt-v2v before 0.8.4 does not preserve the VNC console password when converting a guest, which allows local users to bypass the intended VNC authentication by connecting without a password.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2011-1615.NASL
    descriptionAn updated virt-v2v package that fixes one security issue and several bugs is now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having low security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. virt-v2v is a tool for converting and importing virtual machines to libvirt-managed KVM (Kernel-based Virtual Machine), or Red Hat Enterprise Virtualization. Using virt-v2v to convert a guest that has a password-protected VNC console to a KVM guest removed that password protection from the converted guest: after conversion, a password was not required to access the converted guest
    last seen2020-06-01
    modified2020-06-02
    plugin id64008
    published2013-01-24
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/64008
    titleRHEL 6 : virt-v2v (RHSA-2011:1615)
  • NASL familyScientific Linux Local Security Checks
    NASL idSL_20111206_VIRT_V2V_ON_SL6_X.NASL
    descriptionvirt-v2v is a tool for converting and importing virtual machines to libvirt-managed KVM (Kernel-based Virtual Machine). Using virt-v2v to convert a guest that has a password-protected VNC console to a KVM guest removed that password protection from the converted guest: after conversion, a password was not required to access the converted guest
    last seen2020-06-01
    modified2020-06-02
    plugin id61201
    published2012-08-01
    reporterThis script is Copyright (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/61201
    titleScientific Linux Security Update : virt-v2v on SL6.x x86_64

Redhat

advisories
bugzilla
id732421
titleGuest will BSOD if boot from Windows Recovery Console after conversion
oval
OR
  • commentRed Hat Enterprise Linux must be installed
    ovaloval:com.redhat.rhba:tst:20070304026
  • AND
    • commentRed Hat Enterprise Linux 6 is installed
      ovaloval:com.redhat.rhba:tst:20111656003
    • commentvirt-v2v is earlier than 0:0.8.3-5.el6
      ovaloval:com.redhat.rhsa:tst:20111615001
    • commentvirt-v2v is signed with Red Hat redhatrelease2 key
      ovaloval:com.redhat.rhsa:tst:20111615002
rhsa
idRHSA-2011:1615
released2011-12-05
severityLow
titleRHSA-2011:1615: virt-v2v security and bug fix update (Low)
rpmsvirt-v2v-0:0.8.3-5.el6