ALT-PU-2017-2266-1
Package libvncserver updated to version 0.9.11-alt1.S1 for branch sisyphus in task 188474.
Closed vulnerabilities
BDU:2020-00673
Уязвимость компонента rfbproto.c кроссплатформенной библиотеки LibVNCServer, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании и получить несанкционированный доступ к конфиденциальным данным
BDU:2020-00674
Уязвимость компонента ultra.c кроссплатформенной библиотеки LibVNCServer, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании и получить несанкционированный доступ к конфиденциальным данным
Modified: 2024-11-21
CVE-2016-9941
Heap-based buffer overflow in rfbproto.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message containing a subrectangle outside of the client drawing area.
- DSA-3753
- DSA-3753
- 95170
- 95170
- https://github.com/LibVNC/libvncserver/pull/137
- https://github.com/LibVNC/libvncserver/pull/137
- https://github.com/LibVNC/libvncserver/releases/tag/LibVNCServer-0.9.11
- https://github.com/LibVNC/libvncserver/releases/tag/LibVNCServer-0.9.11
- [debian-lts-announce] 20191030 [SECURITY] [DLA 1979-1] italc security update
- [debian-lts-announce] 20191030 [SECURITY] [DLA 1979-1] italc security update
- GLSA-201702-24
- GLSA-201702-24
- USN-4587-1
- USN-4587-1
Modified: 2024-11-21
CVE-2016-9942
Heap-based buffer overflow in ultra.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message with the Ultra type tile, such that the LZO payload decompressed length exceeds what is specified by the tile dimensions.
- DSA-3753
- DSA-3753
- 95170
- 95170
- https://github.com/LibVNC/libvncserver/pull/137
- https://github.com/LibVNC/libvncserver/pull/137
- https://github.com/LibVNC/libvncserver/releases/tag/LibVNCServer-0.9.11
- https://github.com/LibVNC/libvncserver/releases/tag/LibVNCServer-0.9.11
- [debian-lts-announce] 20191030 [SECURITY] [DLA 1979-1] italc security update
- [debian-lts-announce] 20191030 [SECURITY] [DLA 1979-1] italc security update
- GLSA-201702-24
- GLSA-201702-24
- USN-4587-1
- USN-4587-1