Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-3385

Опубликовано: 10 авг. 2020
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2020-3385: libvncserver security update (IMPORTANT)

[0.9.11-15.1]

  • Fix NVR Related: #1852356

[0.9.11-15]

  • Fix CVE-2017-18922 Resolves: #1852356

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

libvncserver

0.9.11-15.el8_2.1

libvncserver-devel

0.9.11-15.el8_2.1

Oracle Linux x86_64

libvncserver

0.9.11-15.el8_2.1

libvncserver-devel

0.9.11-15.el8_2.1

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

CVSS3: 9.8
redhat
почти 9 лет назад

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

CVSS3: 9.8
nvd
больше 5 лет назад

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

CVSS3: 9.8
debian
больше 5 лет назад

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 di ...

suse-cvrf
больше 5 лет назад

Security update for LibVNCServer