|
|
Subscribe / Log in / New account

Debian alert DLA-1946-1 (novnc)

From:  Abhijith PA <abhijith@disroot.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 1946-1] novnc security update
Date:  Sat, 5 Oct 2019 20:10:50 +0530
Message-ID:  <1f3499cc-57e4-5989-e369-3473bd8e210c@disroot.org>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Package : novnc Version : 1:0.4+dfsg+1+20131010+gitf68af8af3d-4+deb8u1 CVE ID : CVE-2017-18635 An XSS vulnerability was discovered in noVNC in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name. For Debian 8 "Jessie", this problem has been fixed in version 1:0.4+dfsg+1+20131010+gitf68af8af3d-4+deb8u1. We recommend that you upgrade your novnc packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAl2Yqz4ACgkQhj1N8u2c KO+4gQ/+L5ciWTaSfZvuE/vjtxW7GUTyeRJFa9Jiu95MH+ge2f5eKuRd0aE6Ej6G AN3IhjlNJzVR87zEr6b3pmMItQYYb5c6MtHw2w5I59fmKrbm0z613UBvY9yyGsry 9DEI50yfTTt0k6G4e5H/xaByT1p/APAq8RFMyzNgX/7m45LpWMZ5mB9RiORDL3tN QJN9DDKKJY7LVPSPkrjiI6rkD9/XjqJht6U5+tYsdG8Ctre+zn6ophIAkn0Zzv+6 B5yFFpawSSWfDRxXKrjSC4X+fb52Qn8zPjYl7xcyT8KMZvTp4BptyfDX6m30b/kx InqXJTkA6qPUsAiQtb9YxA/yrcJ5eXxZSJzyoVsU7a862TFXeropsM4hhPxTrgiV cB8mBqXXyZ3VNiPQoledtYank16lUhieLEeG2IgIhjla/y7XlGeWI911e2XNlEbJ hO3/Yxj6YJNZP06FGRtMhpArmaymjiHlWje6WfVdyrSr8mJ9NnGE6eZ2S+ZiuFuk 6Uvc+MUhbLrxvv//zHJpPKZAje9KBwhFxn3G9R/B+SsNmJVdTUsbnULg4CkNF2Ju IgYJx/Szm5Q6LugN3TYWPPCG8qxm7cxd5cGMEiskWddCf86X2AM1enh3Vqnk56lN UPl2ta0uUhAnm5xLKUn3OT2cG2V+fqsG3ZDYXY8Qd7TqyefonPA= =vRSJ -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds