Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2018-1055

Опубликовано: 17 апр. 2018
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2018-1055: libvncserver security update (MODERATE)

[0.9.9-12]

  • Fix CVE-2018-7225 (improper client cut text length sanitization) (bug #1548440)

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

libvncserver

0.9.9-12.el7_5

libvncserver-devel

0.9.9-12.el7_5

Oracle Linux x86_64

libvncserver

0.9.9-12.el7_5

libvncserver-devel

0.9.9-12.el7_5

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.

CVSS3: 5.4
redhat
больше 7 лет назад

An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.

CVSS3: 9.8
nvd
больше 7 лет назад

An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.

CVSS3: 9.8
debian
больше 7 лет назад

An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClie ...

suse-cvrf
больше 7 лет назад

Security update for LibVNCServer