[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 1946-1] novnc security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Package        : novnc
Version        : 1:0.4+dfsg+1+20131010+gitf68af8af3d-4+deb8u1
CVE ID         : CVE-2017-18635


An XSS vulnerability was discovered in noVNC in which the remote VNC
server could inject arbitrary HTML into the noVNC web page via the
messages propagated to the status field, such as the VNC server name.

For Debian 8 "Jessie", this problem has been fixed in version
1:0.4+dfsg+1+20131010+gitf68af8af3d-4+deb8u1.

We recommend that you upgrade your novnc packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAl2Yqz4ACgkQhj1N8u2c
KO+4gQ/+L5ciWTaSfZvuE/vjtxW7GUTyeRJFa9Jiu95MH+ge2f5eKuRd0aE6Ej6G
AN3IhjlNJzVR87zEr6b3pmMItQYYb5c6MtHw2w5I59fmKrbm0z613UBvY9yyGsry
9DEI50yfTTt0k6G4e5H/xaByT1p/APAq8RFMyzNgX/7m45LpWMZ5mB9RiORDL3tN
QJN9DDKKJY7LVPSPkrjiI6rkD9/XjqJht6U5+tYsdG8Ctre+zn6ophIAkn0Zzv+6
B5yFFpawSSWfDRxXKrjSC4X+fb52Qn8zPjYl7xcyT8KMZvTp4BptyfDX6m30b/kx
InqXJTkA6qPUsAiQtb9YxA/yrcJ5eXxZSJzyoVsU7a862TFXeropsM4hhPxTrgiV
cB8mBqXXyZ3VNiPQoledtYank16lUhieLEeG2IgIhjla/y7XlGeWI911e2XNlEbJ
hO3/Yxj6YJNZP06FGRtMhpArmaymjiHlWje6WfVdyrSr8mJ9NnGE6eZ2S+ZiuFuk
6Uvc+MUhbLrxvv//zHJpPKZAje9KBwhFxn3G9R/B+SsNmJVdTUsbnULg4CkNF2Ju
IgYJx/Szm5Q6LugN3TYWPPCG8qxm7cxd5cGMEiskWddCf86X2AM1enh3Vqnk56lN
UPl2ta0uUhAnm5xLKUn3OT2cG2V+fqsG3ZDYXY8Qd7TqyefonPA=
=vRSJ
-----END PGP SIGNATURE-----


Reply to: