Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 7: MGASA-2020-0374 Moderate: noVNC HTML Injection

mageia
Calendar Grey September 27, 2020
Dist Mageia Esm H88
Mageia 2020-0384 releases updates for noVNC to address a cross-site scripting flaw impacting versions older than 0.6.2.
An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the stat...

Summary

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name. (CVE-2017-18635)

References

- https://bugs.mageia.org/show_bug.cgi?id=27306

- https://ubuntu.com/security/notices/USN-4522-1

- https://www.cve.org/CVERecord?id=CVE-2017-18635

Resolution

SRPMS

- 7/core/novnc-0.5.1-2.1.mga7

Publication date: 27 Sep 2020
URL: https://advisories.mageia.org/MGASA-2020-0374.html
Type: security
CVE: CVE-2017-18635

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here