CVE-2013-7436
Publication date 10 April 2015
Last updated 24 July 2024
Ubuntu priority
noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Status
Package | Ubuntu Release | Status |
---|---|---|
novnc | ||
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |