*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Marc Deslauriers 
(mdeslaur):

Binary package hint: vino

When enabling the VNC server in System → Preferences → Remote Desktop,
Vino establishes an HTTP connect to an external website to check if
connectivity is able:

[pid  5841] connect(17, {sa_family=AF_INET, sin_port=htons(80),
sin_addr=inet_addr("189.38.80.51")}, 16) = -1 EINPROGRESS (Operation now
in progress)

http://git.gnome.org/browse/vino/tree/capplet/webservices - defines the
URLs to use to check connectivity while:

- http://git.gnome.org/browse/vino/tree/capplet/vino-url-webservice.c

Appears to establish the connection. This is sub-optimal and something
such as querying NetworkManager over D-Bus should be used instead.

** Affects: vino (Ubuntu)
     Importance: Undecided
         Status: New

-- 
vino establishes a HTTP connection to check connectivity
https://bugs.edge.launchpad.net/bugs/608701
You received this bug notification because you are a member of Ubuntu Bugs, 
which is a direct subscriber.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to