Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-3281

Опубликовано: 04 авг. 2020
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2020-3281: libvncserver security update (IMPORTANT)

[0.9.9-14.1]

  • Fix CVE-2017-18922 Resolves: #1852509

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

libvncserver

0.9.9-14.el7_8.1

libvncserver-devel

0.9.9-14.el7_8.1

Oracle Linux x86_64

libvncserver

0.9.9-14.el7_8.1

libvncserver-devel

0.9.9-14.el7_8.1

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

CVSS3: 9.8
redhat
почти 9 лет назад

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

CVSS3: 9.8
nvd
больше 5 лет назад

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

CVSS3: 9.8
debian
больше 5 лет назад

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 di ...

suse-cvrf
больше 5 лет назад

Security update for LibVNCServer