Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-1165
HistoryMar 12, 2013 - 12:00 a.m.

CVE-2011-1165

2013-03-1200:00:00
ubuntu.com
ubuntu.com
18

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS

0.012

Percentile

85.5%

Vino, possibly before 3.2, does not properly document that it opens ports
in UPnP routers when the “Configure network to automatically accept
connections” setting is enabled, which might make it easier for remote
attackers to perform further attacks.

Notes

Author Note
jdstrand no upstream fix
mdeslaur oneiric+ has more explicit text: “Automatically configure UPnP router to open and forward ports”. Marking as not-affected.

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS

0.012

Percentile

85.5%