CVE-2011-1165: Medium severity david king vino vulnerability

Published Feb 20, 2011
·
Updated

Created attachment 479752 [details] Screenshot of what UPnP means.

Description of problem: System ---> Preferences ---> Remote Desktop does not sufficiently warn that UPnP is being used to open ports on your router. When end user is testing, he very well may disables confirmation and password. Because there is no very explicit UPnP warning, he just unwittingly enabled anybody on the internet to connect to his desktop.

Version-Release number of selected component (if applicable): vino 2.32.0-1.fc14

How reproducible: parts always, UPnP success at opening router port varies. Sometimes, it successfully opens a port, other times it does not.

Steps to Reproduce: 1.System --> Preferences --> Remote Desktop 2.uncheck confirmation, uncheck password 3.check "Configure network to automatically accept connections." Actual results: Changed router configuration without telling user. Expose machine to internet usage with no password and no confirmation.

Expected results: Text should be more explicit that this uses UPnP. The pop up message mentions UPnP, but it at least should be a red warning. Especially when no confirmation and no password is required.

Additional info: All machines tested have multiple NICs. selinux enabled. iptables turned off. It may take several attempts to open up ports on router using UPnP. Not sure what happens upon reboot of workstation and router -- UPnP may work to open ports that were not open before.

Other sources

Vino, possibly before 3.2, does not properly document that it opens ports in UPnP routers when the "Configure network to automatically accept connections" setting is enabled, which might make it easier for remote attackers to perform further attacks.

MITRE

Affected Software

103 affected components
David King Vino=2.23.5
David King Vino=2.21.92
David King Vino=2.23
David King Vino=2.17.92
David King Vino=2.19.5
David King Vino=3.1.5
David King Vino=2.32.0
David King Vino=2.19
David King Vino=2.27.5
David King Vino=3.0.1
David King Vino=2.22
David King Vino=2.32.1
David King Vino=2.25.91
David King Vino=2.23.92
David King Vino=2.21.2
David King Vino=2.11.1.2
David King Vino=2.25.3
David King Vino=2.31.91
David King Vino=2.11.1
David King Vino=2.18
David King Vino=2.21.1
David King Vino=2.10
David King Vino=2.7.92
David King Vino=2.7.91
David King Vino=2.24.1
David King Vino=2.7.4.91
David King Vino=2.28.2
David King Vino=3.1.90
David King Vino=2.26.2
David King Vino=2.7.3.1
David King Vino=2.19.92
David King Vino=2.11.92
David King Vino=2.11
David King Vino=2.99.2
David King Vino=2.25.92
David King Vino=3.0.0
David King Vino=2.20.1
David King Vino=2.27.90
David King Vino=2.27
David King Vino=3.1.1
David King Vino=2.31.4
David King Vino=2.16
David King Vino=3.1
David King Vino=2.8.1
David King Vino=2.7.3
David King Vino=2.7.4
David King Vino=2.13.5
David King Vino=2.24
David King Vino=2.11.1.1
David King Vino=3.1.91
David King Vino=0.14
David King Vino=2.11.90
David King Vino=2.28.1
David King Vino=2.7.4.90
David King Vino=2.23.91
David King Vino=2.26
David King Vino=2.99.0
David King Vino=2.8.0.1
David King Vino=2.17.4
David King Vino=2.99.3
David King Vino=2.99.1
David King Vino=2.25.4
David King Vino=2.27.92
David King Vino=3.1.2
David King Vino=2.14
David King Vino=2.9
David King Vino=2.13
David King Vino=2.7.90
David King Vino=2.21
David King Vino=2.28.3
David King Vino=0.12
David King Vino=2.26.1
David King Vino=2.28
David King Vino=2.17
David King Vino=2.7
David King Vino=3.0.3
David King Vino=2.25.90
David King Vino=2.9.2
David King Vino=2.12
David King Vino=2.21.91
David King Vino=2.20
David King Vino=3.1.3
David King Vino=2.32.2
David King Vino=2.21.3
David King Vino=2.17.5
David King Vino=3.0.2
David King Vino=2.25
David King Vino=2.27.91
David King Vino=2.8.0
David King Vino=2.8
David King Vino=2.25.5
David King Vino=2.22.2
David King Vino=2.21.90
David King Vino=2.18.1
David King Vino=2.99.5
David King Vino=3.1.4
David King Vino=2.17.2
David King Vino=2.99.4
David King Vino=2.22.1
David King Vino=2.23.90
David King Vino=2.19.90
David King Vino<=3.1.92
David King Vino=2.15

Event History

Feb 20, 2011
Data Sourced
10:40 AM
DescriptionSeverityAffected Software
Mar 12, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2011-1165?

CVE-2011-1165 is assigned a medium severity due to its potential for exploitation leading to unauthorized access.

2

How do I fix CVE-2011-1165?

To fix CVE-2011-1165, upgrade Vino to version 2.32.2 or later, in which the vulnerability is patched.

3

Which versions of Vino are affected by CVE-2011-1165?

CVE-2011-1165 affects multiple versions of Vino, including several iterations from 0.12 up to 3.1.92.

4

What type of vulnerability is CVE-2011-1165?

CVE-2011-1165 is a security vulnerability related to remote code execution and unauthorized access.

5

What impact does CVE-2011-1165 have on users?

The impact of CVE-2011-1165 on users can include unauthorized control over their systems, leading to privacy breaches and data loss.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203