QID 198198
Date Published: 2021-03-23
QID 198198: Ubuntu Security Notification for noVNC vulnerability (USN-4522-1)
It was discovered that noVNC did not properly manage certain messages, resulting in the remote VNC server injecting arbitrary HTML into the noVNC web page.
An attacker could use this issue to conduct cross-site scripting (XSS) attacks. (CVE-2017-18635)
Solution
Refer to Ubuntu advisory USN-4522-1 for affected packages and patching details, or update with your package manager.
Vendor References
- USN-4522-1 -
ubuntu.com/security/notices/USN-4522-1
CVEs related to QID 198198
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-4522-1 | 16.04 (Xenial) on src | novnc |
|