CVE-2015-0236

low
Published 2015-01-29 · Modified 2026-05-06
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-0236

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://security.libvirt.org/2015/0001.html

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2015-0236.html

OS impact

OSVersionStatusFixed in
suse slesaffected
ubuntu ubuntu12.04affected
ubuntu ubuntu14.04affected
ubuntu ubuntu15.04affected
ubuntu ubuntu15.10affected
suse suse13.1not-affected
suse suse13.2not-affected
debian debianbookwormfixed1.2.9-8
debian debianbullseyefixed1.2.9-8
debian debianforkyfixed1.2.9-8
debian debiansidfixed1.2.9-8
debian debiantrixiefixed1.2.9-8
redhat rhel7.0affected

Application impact

VendorProductVersionsFixed
redhatlibvirt{"endIncluding":"1.2.11"}
redhatlibvirt1.2.0
redhatlibvirt1.2.1
redhatlibvirt1.2.2
redhatlibvirt1.2.3
redhatlibvirt1.2.4
redhatlibvirt1.2.5
redhatlibvirt1.2.6
redhatlibvirt1.2.7
redhatlibvirt1.2.8
redhatlibvirt1.2.9
redhatlibvirt1.2.10

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.