CVE-2013-7436
Publication date 10 April 2015
Last updated 24 July 2024
Ubuntu priority
Description
noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Status
| Package | Ubuntu Release | Status | 
|---|---|---|
| novnc | ||
| 18.04 LTS bionic | 
                                Not affected 
                                
                               | |
| 16.04 LTS xenial | 
                                Not affected 
                                
                               | |
| 14.04 LTS trusty | Not in release | |