| Main Archive Page > Month Archives > oss-security archives |
> Upstream changes have introduced a flaw by disabling all authentication when
> the password was cleared with upstream commit [1].
>
> [1]
> http://www.qemu.com/qemu.git/commit/?id=52c18be9e99dabe295321153fda7fce9f76647ac"
Confirmed vulnerable in qemu-kvm source code 0.10.6, fixed in 0.11.0
http://sourceforge.net/projects/kvm/files/qemu-kvm/
-- Kurt Seifried kurt@seifried.org skype: 1-703-879-3176