Where
-Infinity
0

Vendor Risk Score

See how david king compares to other vendors in security performance

View Risk Score →
Severity
7.1
Input Validation
AV:N/AC:M/Au:N/C:N/I:N/A:C

The vinoserverclientdatapending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authentication, which allows remote attackers to cause a denial of service (infinite loop, CPU and disk consumption) via multiple crafted requests during authentication.

First published (updated )
Severity
5.1
AV:N/AC:H/Au:N/C:P/I:P/A:P

Created attachment 479752 [details] Screenshot of what UPnP means.

Description of problem: System ---> Preferences ---> Remote Desktop does not sufficiently warn that UPnP is being used to open ports on your router. When end user is testing, he very well may disables confirmation and password. Because there is no very explicit UPnP warning, he just unwittingly enabled anybody on the internet to connect to his desktop.

Version-Release number of selected component (if applicable): vino 2.32.0-1.fc14

How reproducible: parts always, UPnP success at opening router port varies. Sometimes, it successfully opens a port, other times it does not.

Steps to Reproduce: 1.System --> Preferences --> Remote Desktop 2.uncheck confirmation, uncheck password 3.check "Configure network to automatically accept connections." Actual results: Changed router configuration without telling user. Expose machine to internet usage with no password and no confirmation.

Expected results: Text should be more explicit that this uses UPnP. The pop up message mentions UPnP, but it at least should be a red warning. Especially when no confirmation and no password is required.

Additional info: All machines tested have multiple NICs. selinux enabled. iptables turned off. It may take several attempts to open up ports on router using UPnP. Not sure what happens upon reboot of workstation and router -- UPnP may work to open ports that were not open before.

1 / 2
Source: Red Hat
First published (updated )
Severity
5
Infoleak
AV:N/AC:L/Au:N/C:P/I:N/A:N

Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.

First published (updated )
Severity
4.6
AV:N/AC:H/Au:S/C:P/I:P/A:P

Vino before 2.99.4 can connect external networks contrary to the statement in the vino-preferences dialog box, which might make it easier for remote attackers to perform attacks.

1 / 2
Source: MITRE
First published (updated )
Severity
3.5
Buffer Overflow
AV:N/AC:M/Au:S/C:N/I:N/A:P

An out of bounds read flaw was found in the way vino, remote desktop system for GNOME processed certain framebuffer update requests from VNC client, when raw encoding was used. An attacker could use this flaw to send a specially-crafted request to vino, causing it to crash.

Upstream bug report: [1] https://bugzilla.gnome.org/showbug.cgi?id=641802

Relevant upstream commits (for gnome-2-28, gnome-2-30, gnome-2-32, gnome-3-0 and master branches):

[2] http://git.gnome.org/browse/vino/commit/?id=dff52694a384fe95195f2211254026b752d63ec4 [3] http://git.gnome.org/browse/vino/commit/?id=0c2c9175963fc56bf2af10e42867181332f96ce0 [4] http://git.gnome.org/browse/vino/commit/?id=e17bd4e369f90748654e31a4867211dc7610975d [5] http://git.gnome.org/browse/vino/commit/?id=456dadbb5c5971d3448763a44c05b9ad033e522f [6] http://git.gnome.org/browse/vino/commit/?id=8beefcf7792d343c10c919ee0c928c81f73b1279

1 / 2
Source: Red Hat
First published (updated )
Severity
3.5
Buffer Overflow
AV:N/AC:M/Au:S/C:N/I:N/A:P

An out of bounds read flaw was found in the way vino, remote desktop system for GNOME processed certain framebuffer update requests from VNC client, when tight encoding was used. An attacker could use this flaw to send a specially-crafted request to vino, causing it to crash.

Upstream bug report: [1] https://bugzilla.gnome.org/showbug.cgi?id=641803 (not public yet) [2] https://bugzilla.gnome.org/showbug.cgi?id=641802 (dedicated to CVE-2011-0904 issue)

Relevant upstream commits (for gnome-2-28, gnome-2-30, gnome-2-32, gnome-3-0 and master branches):

[2] http://git.gnome.org/browse/vino/commit/?id=dff52694a384fe95195f2211254026b752d63ec4 [3] http://git.gnome.org/browse/vino/commit/?id=0c2c9175963fc56bf2af10e42867181332f96ce0 [4] http://git.gnome.org/browse/vino/commit/?id=e17bd4e369f90748654e31a4867211dc7610975d [5] http://git.gnome.org/browse/vino/commit/?id=456dadbb5c5971d3448763a44c05b9ad033e522f [6] http://git.gnome.org/browse/vino/commit/?id=8beefcf7792d343c10c919ee0c928c81f73b1279

1 / 2
Source: Red Hat
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203