Package: anyremote Version: 4.15-1 Severity: wishlist
There are no check for permitted clients on anyremote server. It follows that any paired device can control anyremote server via bluetooth or any client can control server over socket interface. It is very unsecure. My wish is to add filtering by device address (for bluetooth connection) or by password (for socket interface). Additionally, it will be good to have channel encryption for socket and web interfaces. -- System Information: Debian Release: 5.0 APT prefers testing APT policy: (500, 'testing') Architecture: amd64 (x86_64) Kernel: Linux 2.6.26-1-amd64 (SMP w/1 CPU core) Locale: LANG=ru_RU.UTF-8, LC_CTYPE=ru_RU.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/bash Versions of packages anyremote depends on: ii libbluetooth2 3.36-1 Library to use the BlueZ Linux Blu ii libc6 2.7-18 GNU C Library: Shared libraries ii libx11-6 2:1.1.5-2 X11 client-side library ii libxtst6 2:1.0.3-1 X11 Testing -- Resource extension Versions of packages anyremote recommends: ii python 2.5.2-3 An interactive high-level object-o Versions of packages anyremote suggests: pn python-xmmslclient <none> (no description available) -- no debconf information -- To UNSUBSCRIBE, email to [email protected] with a subject of "unsubscribe". Trouble? Contact [email protected]

