Описание
ELSA-2024-0629: tigervnc security update (IMPORTANT)
[1.8.0-31.0.1]
- Dropped xorg-CVE-2023-5367.patch, xorg-CVE-2023-6816.patch, xorg-CVE-2023-6377.patch, xorg-CVE-2023-6478.patch, xorg-CVE-2024-0229-1.patch, xorg-CVE-2024-0229-2.patch, xorg-CVE-2024-0229-3.patch, xorg-CVE-2024-21885.patch, xorg-CVE-2024-21886-1.patch, xorg-CVE-2024-21886-2.patch, xorg-dix-fix-use-after-free-in-input-device-shutdown.patch
[1.8.0-31]
- Fix use after free related to CVE-2024-21886 Resolves: RHEL-20436
- Fix copy/paste error in the DeviceStateNotify Resolves: RHEL-20587
[1.8.0-30]
- Don't try to get pointer position when the pointer becomes a floating device Resolves: RHEL-20436
[1.8.0-29]
- Fix CVE-2024-21886 tigervnc: xorg-x11-server: heap buffer overflow in DisableDevice Resolves: RHEL-20436
- Fix CVE-2024-21885 tigervnc: xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent Resolves: RHEL-20427
- Fix CVE-2024-0229 tigervnc: xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access Resolves: RHEL-20587
- Fix CVE-2023-6816 tigervnc: xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer Resolves: RHEL-21212
Обновленные пакеты
Oracle Linux 7
Oracle Linux aarch64
tigervnc
1.8.0-31.0.1.el7_9
tigervnc-icons
1.8.0-31.0.1.el7_9
tigervnc-license
1.8.0-31.0.1.el7_9
tigervnc-server
1.8.0-31.0.1.el7_9
tigervnc-server-applet
1.8.0-31.0.1.el7_9
tigervnc-server-minimal
1.8.0-31.0.1.el7_9
tigervnc-server-module
1.8.0-31.0.1.el7_9
Oracle Linux x86_64
tigervnc
1.8.0-31.0.1.el7_9
tigervnc-icons
1.8.0-31.0.1.el7_9
tigervnc-license
1.8.0-31.0.1.el7_9
tigervnc-server
1.8.0-31.0.1.el7_9
tigervnc-server-applet
1.8.0-31.0.1.el7_9
tigervnc-server-minimal
1.8.0-31.0.1.el7_9
tigervnc-server-module
1.8.0-31.0.1.el7_9