Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2017:0519-1

Опубликовано: 20 фев. 2017
Источник: suse-cvrf

Описание

Security update for tigervnc

This update for tigervnc provides the following fixes:

  • Prevent malicious server from crashing a server via a buffer overflow, a similar flaw as the LibVNCServer issues CVE-2016-9941 and CVE-2016-9942.. (bsc#1019274)
  • CVE-2016-10207: Prevent potential crash due to insufficient clean-up after failure to establish TLS connection. (bsc#1023012)

Список пакетов

SUSE Linux Enterprise Desktop 12 SP1
tigervnc-1.4.3-19.1
xorg-x11-Xvnc-1.4.3-19.1
SUSE Linux Enterprise Server 12 SP1
tigervnc-1.4.3-19.1
xorg-x11-Xvnc-1.4.3-19.1
SUSE Linux Enterprise Server for SAP Applications 12 SP1
tigervnc-1.4.3-19.1
xorg-x11-Xvnc-1.4.3-19.1

Описание

The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP1:tigervnc-1.4.3-19.1
SUSE Linux Enterprise Desktop 12 SP1:xorg-x11-Xvnc-1.4.3-19.1
SUSE Linux Enterprise Server 12 SP1:tigervnc-1.4.3-19.1
SUSE Linux Enterprise Server 12 SP1:xorg-x11-Xvnc-1.4.3-19.1

Ссылки

Описание

Heap-based buffer overflow in rfbproto.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message containing a subrectangle outside of the client drawing area.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP1:tigervnc-1.4.3-19.1
SUSE Linux Enterprise Desktop 12 SP1:xorg-x11-Xvnc-1.4.3-19.1
SUSE Linux Enterprise Server 12 SP1:tigervnc-1.4.3-19.1
SUSE Linux Enterprise Server 12 SP1:xorg-x11-Xvnc-1.4.3-19.1

Ссылки

Описание

Heap-based buffer overflow in ultra.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message with the Ultra type tile, such that the LZO payload decompressed length exceeds what is specified by the tile dimensions.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP1:tigervnc-1.4.3-19.1
SUSE Linux Enterprise Desktop 12 SP1:xorg-x11-Xvnc-1.4.3-19.1
SUSE Linux Enterprise Server 12 SP1:tigervnc-1.4.3-19.1
SUSE Linux Enterprise Server 12 SP1:xorg-x11-Xvnc-1.4.3-19.1

Ссылки