oss-sec mailing list archives
CVE Request / Discussion -- vino -- reports the desktop being reachable only over the local network, when reachable from everywhere
From: Jan Lieskovsky <jlieskov () redhat com>
Date: Mon, 14 Mar 2011 16:00:14 +0100
Hello Josh, Steve, David, vendors, this is due the following vino deficiency: [1] https://bugzilla.redhat.com/show_bug.cgi?id=553477#c0 [2] https://bugzilla.redhat.com/show_bug.cgi?id=678846 As noted in [1] Vino may incorrectly report, that relevant user desktop is reachable only over local network, when in fact it's reachable from everywhere. As this is issue slightly on the border, not sure it should receive a CVE identifier, so Cc-ed David Woodhouse to elaborate more on issue impact if necessary. Under my opinion, the trust boundary is crossed (it is wrongly reported to the the user, they have a secure setup, when they do not have it and otherwise would perform steps to correct the settings). But left the final decision for further discussion. What are the thoughts of the others? Should this one get a CVE identifier or not? Upstream bug report: [3] https://bugzilla.gnome.org/show_bug.cgi?id=596190 Ubuntu bug report (IPv6 specific): [4] https://bugs.launchpad.net/ubuntu/+source/vino/+bug/344489 To David King -- David, what are the upstream plans for this issue? Is there by any chance upstream patch for the bug [3] yet? Thanks && Regards, Jan. -- Jan iankko Lieskovsky / Red Hat Security Response Team
Current thread:
- CVE Request / Discussion -- vino -- reports the desktop being reachable only over the local network, when reachable from everywhere Jan Lieskovsky (Mar 14)
- Re: CVE Request / Discussion -- vino -- reports the desktop being reachable only over the local network, when reachable from everywhere David King (Mar 14)
- Re: CVE Request / Discussion -- vino -- reports the desktop being reachable only over the local network, when reachable from everywhere Josh Bressers (Mar 14)
- Re: CVE Request / Discussion -- vino -- reports the desktop being reachable only over the local network, when reachable from everywhere Steven M. Christey (Mar 14)
- Re: CVE Request / Discussion -- vino -- reports the desktop being reachable only over the local network, when reachable from everywhere Josh Bressers (Mar 15)
- Re: CVE Request / Discussion -- vino -- reports the desktop being reachable only over the local network, when reachable from everywhere David Woodhouse (Mar 16)
- Re: CVE Request / Discussion -- vino -- reports the desktop being reachable only over the local network, when reachable from everywhere David King (Mar 16)
- Re: CVE Request / Discussion -- vino -- reports the desktop being reachable only over the local network, when reachable from everywhere David Woodhouse (Mar 16)
- Re: CVE Request / Discussion -- vino -- reports the desktop being reachable only over the local network, when reachable from everywhere Josh Bressers (Mar 16)
- Re: CVE Request / Discussion -- vino -- reports the desktop being reachable only over the local network, when reachable from everywhere David Woodhouse (Mar 16)
- Re: CVE Request / Discussion -- vino -- reports the desktop being reachable only over the local network, when reachable from everywhere David Woodhouse (Mar 16)