oss-sec mailing list archives

Re: CVE Request / Discussion -- vino -- reports the desktop being reachable only over the local network, when reachable from everywhere


From: David Woodhouse <dwmw2 () infradead org>
Date: Wed, 16 Mar 2011 11:40:32 +0000

On Wed, 2011-03-16 at 12:02 +0100, David King wrote:
It should be noted that the UPnP feature is disabled by default, so the 
user has the option to *enable* it. I concede that the string presented 
in the UI needs improvement. 

That isn't CVE-worthy, though, surely?

Of course, I agree that indication of the consequences would be
appropriate, 

That's CVE-2011-1164.

and also disallowing the 'none' authentication method if UPnP is enabled. 

And that, again, is not at all specific to UPnP.

Disallowing the 'none' authentication method is would be appropriate
whenever the machine is accessible from the outside world, whether
that's through UPnP or just by listening on a publicly-available IP
address.

-- 
dwmw2


Current thread: