Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-7436

Опубликовано: 10 апр. 2015
Источник: debian
EPSS Низкий

Описание

noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
novncfixed1:0.4+dfsg+1+20131010+gitf68af8af3d-4package
novncnot-affectedwheezypackage

Примечания

  • https://github.com/kanaka/noVNC/commit/ad941faddead705cd611921730054767a0b32dcd

  • https://www.openwall.com/lists/oss-security/2015/02/17/1

EPSS

Процентиль: 81%
0.02168
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

redhat
почти 13 лет назад

noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

nvd
больше 11 лет назад

noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

github
около 4 лет назад

noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

EPSS

Процентиль: 81%
0.02168
Низкий