Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-7436

Опубликовано: 10 апр. 2015
Источник: debian
EPSS Низкий

Описание

noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
novncfixed1:0.4+dfsg+1+20131010+gitf68af8af3d-4package
novncnot-affectedwheezypackage

Примечания

  • https://github.com/kanaka/noVNC/commit/ad941faddead705cd611921730054767a0b32dcd

  • https://www.openwall.com/lists/oss-security/2015/02/17/1

EPSS

Процентиль: 69%
0.00614
Низкий

Связанные уязвимости

ubuntu
почти 11 лет назад

noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

redhat
больше 12 лет назад

noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

nvd
почти 11 лет назад

noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

github
больше 3 лет назад

noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

EPSS

Процентиль: 69%
0.00614
Низкий