Input validation error in Vino - CVE-2011-1165

 

Input validation error in Vino - CVE-2011-1165

Published: March 13, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU43008
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-1165
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Vino, possibly before 3.2, does not properly document that it opens ports in UPnP routers when the "Configure network to automatically accept connections" setting is enabled, which might make it easier for remote attackers to perform further attacks.


Affected software

Vino

How to mitigate CVE-2011-1165

Install update from vendor's website.


External References

Related Security Bulletins