VulnerabilityModified
CVE-2011-1165
Vino, possibly before 3.2, does not properly document that it opens ports in UPnP routers when the "Configure network to automatically accept connections" setting is enabled, which might make it easier for remote attackers to perform further attacks.
MEDIUM 5.1EPSS 2.27%
Does this matter?
Lower severity and a low EPSS score (2.27%). Track it; it rarely justifies an emergency change on its own.
Description
Vino, possibly before 3.2, does not properly document that it opens ports in UPnP routers when the "Configure network to automatically accept connections" setting is enabled, which might make it easier for remote attackers to perform further attacks.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 2.27% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- david king/vino
- Source
- secalert@redhat.com
References
- http://git.gnome.org/browse/vino/commit/?id=410bbf8e284409bdef02322af4d4a3a388419566Exploit, Patch
- http://rhn.redhat.com/errata/RHSA-2013-0169.html
- http://www.dslreports.com/forum/r25446313-Ubuntu-computer-hijacked-by-hacker~start=40
- https://bugzilla.gnome.org/show_bug.cgi?id=594521
- https://bugzilla.redhat.com/show_bug.cgi?id=678846
- http://git.gnome.org/browse/vino/commit/?id=410bbf8e284409bdef02322af4d4a3a388419566Exploit, Patch
- http://rhn.redhat.com/errata/RHSA-2013-0169.html
- http://www.dslreports.com/forum/r25446313-Ubuntu-computer-hijacked-by-hacker~start=40
- https://bugzilla.gnome.org/show_bug.cgi?id=594521
- https://bugzilla.redhat.com/show_bug.cgi?id=678846
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.