|
From: | Niccolò Belli |
Subject: | Re: [Qemu-devel] [Spice-devel] Always get Invalid password while trying to connect to spice server |
Date: | Thu, 27 Dec 2018 15:51:40 +0100 |
User-agent: | Trojita/v0.7-361-gfee56b6f; Qt/5.12.0; xcb; Linux; Arch Linux |
On mercoledì 26 dicembre 2018 13:38:28 CET, Frediano Ziglio wrote:
Yes, this looks like a format string error in the upper (not into spice) layer.This potentially is a security problem.
Considering the spice server is exposed to the internet this is definitely worth investigating.
The specific '%' character could be the issue, can you try others ('!', '@' andso on) ?
I tried several other special characters and they all seems to work, expect for "Password&&" which gets converted to "Password&&" (if I type "Password&&" it works).
Niccolo'
[Prev in Thread] | Current Thread | [Next in Thread] |