Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended.Referenceshttp://lists.gnu.org/archive/html/qemu-devel/2008-12/msg00498.htmlhttp://secunia.com/advisories/35062https://exchange.xforce.ibmcloud.com/vulnerabilities/47683http://lists.gnu.org/archive/html/qemu-devel/2008-11/msg01224.htmlhttp://secunia.com/advisories/34642http://svn.savannah.gnu.org/viewvc/?view=rev&root=qemu&revision=5966http://www.securityfocus.com/bid/33020http://www.ubuntu.com/usn/usn-776-1http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.htmlhttp://secunia.com/advisories/33568http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.htmlhttp://svn.savannah.gnu.org/viewvc/trunk/monitor.c?root=qemu&r1=5966&r2=5965&pathrev=5966