Bug#613273: vinagre connecting to remote IP addresses

Gary Koskenmaki garywk at cableone.net
Sun Feb 13 20:25:24 UTC 2011


Package: vinagre
Version: 2.30.3-1
Severity: normal

vinagre is phoning home upon being enabled.  It is connecting to IP addresses that resolve to .br domains.  What's with this?  I consider this to be a major security problem.  No software that enables sharing a desktop should ever connect to the internet, or open ports via upnp, without telling the user at the time it does so.  This "feature", if that's what it truly is, should not be a default, but should be an opt-in, and should warn users about the consequences.  Not everyone who enables this wants a firewall port opened as they may use this feature on their LAN, and no place else.  I sure wouldn't use the protocol over the internet without tunnelling it over ssh.    

-- System Information:
Debian Release: 6.0
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.32-5-686-bigmem (SMP w/1 CPU core)
Locale: LANG=en_US.ISO-8859-15, LC_CTYPE=en_US.ISO-8859-15 (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/dash

Versions of packages vinagre depends on:
ii  gconf2                 2.28.1-6          GNOME configuration database syste
ii  libatk1.0-0            1.30.0-1          The ATK accessibility toolkit
ii  libavahi-common3       0.6.27-3          Avahi common library
ii  libavahi-gobject0      0.6.27-3          Avahi GObject library
ii  libavahi-ui0           0.6.27-3          Avahi GTK+ User interface library
ii  libbonobo2-0           2.24.3-1          Bonobo CORBA interfaces library
ii  libc6                  2.11.2-11         Embedded GNU C Library: Shared lib
ii  libcairo2              1.8.10-6          The Cairo 2D vector graphics libra
ii  libdbus-1-3            1.2.24-4          simple interprocess messaging syst
ii  libdbus-glib-1-2       0.88-2.1          simple interprocess messaging syst
ii  libfontconfig1         2.8.0-2.1         generic font configuration library
ii  libfreetype6           2.4.2-2.1         FreeType 2 font engine, shared lib
ii  libgconf2-4            2.28.1-6          GNOME configuration database syste
ii  libglib2.0-0           2.24.2-1          The GLib library of C routines
ii  libgnome-keyring0      2.30.1-1          GNOME keyring services library
ii  libgtk-vnc-1.0-0       0.4.1-4           A VNC viewer widget for GTK+ (runt
ii  libgtk2.0-0            2.20.1-2          The GTK+ graphical user interface 
ii  libpanel-applet2-0     2.30.2-3          library for GNOME Panel applets
ii  libpango1.0-0          1.28.3-1+squeeze1 Layout and rendering of internatio
ii  libtelepathy-glib0     0.11.11-1         Telepathy framework - GLib library
ii  libvte9                1:0.24.3-2        Terminal emulator widget for GTK+ 
ii  libx11-6               2:1.3.3-4         X11 client-side library
ii  libxml2                2.7.8.dfsg-2      GNOME XML library

vinagre recommends no packages.

vinagre suggests no packages.

-- no debconf information






More information about the pkg-gnome-maintainers mailing list