Recommended update for novnc

Announcement ID: SUSE-RU-2017:2297-1
Rating: low
References:
Affected Products:
  • SUSE Linux Enterprise High Performance Computing 12 SP2
  • SUSE Linux Enterprise Server 12 SP2
  • SUSE OpenStack Cloud 7

An update that has one fix can now be installed.

Description:

This update provides novnc 0.6.2, which brings the following fixes and enhancements:

  • Fixes a XSS issue in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
  • Removes support for legacy browsers, namely IE9 and below. IE10 may receive "best-effort" support. IE 11+, Edge, Firefox 31+, and Chrome 44+ continue to be supported.

For a comprehensive list of changes please refer to the Release Notes at https://github.com/novnc/noVNC/releases

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE OpenStack Cloud 7
    zypper in -t patch SUSE-OpenStack-Cloud-7-2017-1413=1

Package List:

  • SUSE OpenStack Cloud 7 (x86_64)
    • novnc-0.6.2-2.5.1

References: