-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2854-1 debian-...@lists.debian.org https://www.debian.org/lts/security/ Utkarsh Gupta December 27, 2021 https://wiki.debian.org/LTS - -----------------------------------------------------------------------
Package : novnc Version : 1:0.4+dfsg+1+20131010+gitf68af8af3d-6+deb9u1 CVE ID : CVE-2017-18635 An XSS vulnerability was discovered in noVNC, a HTML5 VNC client, in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name. For Debian 9 stretch, this problem has been fixed in version 1:0.4+dfsg+1+20131010+gitf68af8af3d-6+deb9u1. We recommend that you upgrade your novnc packages. For the detailed security status of novnc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/novnc Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmHK6yoACgkQgj6WdgbD S5apRw/+OE0w9gvG/OIgiqPUo5qnaAeDhgeQUoUl3LjuaKVIVaEsZVukyT+6Uj6V yl0Fp0wvlgjxBOJiA+66OQqs6eLYULDZufxQ01+OHRQtLXK/avjkpDGQsKGqhBm3 AxwljBjLdRfYxz+gfPYjtS63hcVrzaUWTLl7lrKIOc+Cy4eK7Z9/w7QcSeXIrPnt MlIBh1kwnrGHOAKLPrZfHTaZUef3qIrgXD+bqxM4qYE4lCywqMlRiZR+xQizVYwv vZTnifv4Ta/zkgy4ddBU7nluuA+2/csvlzO4R+AqLFRqkDYGUUIEk+vWhbQBSDZc HbNa5r2f57g3Y+jAc/qNRBRyfWbAFy6hpoi4PGpZ0Of3JNPEHYaURP3CWFz16iSS HlJcy7BNBtplIpDPchSKGwSo2ktM04SPDgBvzO16JeWyfgBYnF3VhcOyRvaVmrv5 BvCQHdILeVAeRrlh5i0YnGMMQgd0YIWCnz2lTXRLrtLfcEKjZ6l04rqXO2x7F9cQ JE0ea3kschBV1ERDfWmGiI0wzQEX6cVyOii60BG8IN8x+C82ZaRyXbraft/OOKNM dX02aOJp0jPXpDIh6329+K17jyNLlMvH9JZBAixjq5fZzqVL/DCf9BV46acY3Ph1 KYDp+YpG/EAwv9YeQvSrwPPk5dK3ZlUp4a0tnwJedW3BmFu0RWk= =HCIH -----END PGP SIGNATURE-----