Candidate: CVE-2011-1165 PublicDate: 2013-03-12 23:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1165 Description: Vino, possibly before 3.2, does not properly document that it opens ports in UPnP routers when the "Configure network to automatically accept connections" setting is enabled, which might make it easier for remote attackers to perform further attacks. Ubuntu-Description: Notes: jdstrand> no upstream fix mdeslaur> oneiric+ has more explicit text: "Automatically configure UPnP mdeslaur> router to open and forward ports". Marking as not-affected. Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_vino: upstream_vino: needs-triage hardy_vino: ignored (reached end-of-life) lucid_vino: ignored (reached end-of-life) maverick_vino: ignored (reached end-of-life) natty_vino: ignored (reached end-of-life) oneiric_vino: not-affected (3.2.0-0ubuntu1.1) precise_vino: not-affected (3.4.2-0ubuntu1.1) quantal_vino: not-affected (3.5.92-0ubuntu1) raring_vino: not-affected (3.5.92-0ubuntu1) devel_vino: not-affected (3.5.92-0ubuntu1)