Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 16 Mar 2011 12:02:28 +0100
From: David King <amigadave@...gadave.com>
To: David Woodhouse <dwmw2@...radead.org>
Cc: Josh Bressers <bressers@...hat.com>, oss-security@...ts.openwall.com,
	Mark McLoughlin <mark@...net.ie>,
	"Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE Request / Discussion -- vino -- reports the
 desktop being reachable only over the local network, when reachable from
 everywhere

On 2011-03-16 10:47, David Woodhouse <dwmw2@...radead.org> wrote:
>On Tue, 2011-03-15 at 17:10 -0400, Josh Bressers wrote:
>>
>> Issue #2
>>
>> Vino can open ports via uPnP without alerting the user.
>> https://bugzilla.redhat.com/show_bug.cgi?id=678846
>>
>> Use CVE-2011-1165

[snip]

>There *is* an option to disable this feature, if the user really wants
>to. And of course it should be clearly indicated that the service is
>available to the public; but *that* is what CVE-2011-1164 is for.

It should be noted that the UPnP feature is disabled by default, so the 
user has the option to *enable* it. I concede that the string presented 
in the UI needs improvement. Of course, I agree that indication of the 
consequences would be appropriate, and also disallowing the 'none' 
authentication method if UPnP is enabled.

-- 
http://amigadave.com/

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.