Package: anyremote
Version: 4.15-1
Severity: wishlist

There are no check for permitted clients on anyremote server.
It follows that any paired device can control anyremote server via
bluetooth or any client can control server over socket interface.

It is very unsecure. My wish is to add filtering by device address
(for bluetooth connection) or by password (for socket interface).
Additionally, it will be good to have channel encryption for socket and
web interfaces.

-- System Information:
Debian Release: 5.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.26-1-amd64 (SMP w/1 CPU core)
Locale: LANG=ru_RU.UTF-8, LC_CTYPE=ru_RU.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages anyremote depends on:
ii  libbluetooth2                 3.36-1     Library to use the BlueZ Linux Blu
ii  libc6                         2.7-18     GNU C Library: Shared libraries
ii  libx11-6                      2:1.1.5-2  X11 client-side library
ii  libxtst6                      2:1.0.3-1  X11 Testing -- Resource extension 

Versions of packages anyremote recommends:
ii  python                        2.5.2-3    An interactive high-level object-o

Versions of packages anyremote suggests:
pn  python-xmmslclient            <none>     (no description available)

-- no debconf information



-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to