Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 16 Mar 2011 11:40:32 +0000
From: David Woodhouse <dwmw2@...radead.org>
To: David King <amigadave@...gadave.com>
Cc: Josh Bressers <bressers@...hat.com>, oss-security@...ts.openwall.com, 
 Mark McLoughlin <mark@...net.ie>, "Steven M. Christey"
 <coley@...us.mitre.org>
Subject: Re: CVE Request / Discussion -- vino -- reports the
 desktop being reachable only over the local network, when reachable from
 everywhere

On Wed, 2011-03-16 at 12:02 +0100, David King wrote:
> It should be noted that the UPnP feature is disabled by default, so the 
> user has the option to *enable* it. I concede that the string presented 
> in the UI needs improvement. 

That isn't CVE-worthy, though, surely?

> Of course, I agree that indication of the consequences would be
> appropriate, 

That's CVE-2011-1164.

> and also disallowing the 'none' authentication method if UPnP is enabled. 

And that, again, is not at all specific to UPnP.

Disallowing the 'none' authentication method is would be appropriate
whenever the machine is accessible from the outside world, whether
that's through UPnP or just by listening on a publicly-available IP
address.

-- 
dwmw2

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.