Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2017:1094-1

Опубликовано: 22 апр. 2017
Источник: suse-cvrf

Описание

Security update for tigervnc

This update for tigervnc provides the several fixes.

These security issues were fixed:

  • CVE-2017-7392, CVE-2017-7396: Client can cause leak in VNC server (bsc#1031886)
  • CVE-2017-7395: Authenticated VNC client can crash VNC server (bsc#1031877)
  • CVE-2017-7394: Client can crash or block VNC server (bsc#1031879)
  • CVE-2017-7393: Authenticated client can cause double free in VNC server (bsc#1031875)
  • Prevent buffer overflow in VNC client, allowing for crashing the client (bnc#1032880)

These non-security issues were fixed:

  • Prevent client disconnection caused by invalid cursor manipulation. (bsc#1024929, bsc#1031045)
  • Readd index.vnc. (bsc#1026833)
  • Crop operations to visible screen. (bnc#1032272)

Список пакетов

SUSE Linux Enterprise Desktop 12 SP2
libXvnc1-1.6.0-18.11.1
tigervnc-1.6.0-18.11.1
xorg-x11-Xvnc-1.6.0-18.11.1
SUSE Linux Enterprise Server 12 SP2
libXvnc1-1.6.0-18.11.1
tigervnc-1.6.0-18.11.1
xorg-x11-Xvnc-1.6.0-18.11.1
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
libXvnc1-1.6.0-18.11.1
tigervnc-1.6.0-18.11.1
xorg-x11-Xvnc-1.6.0-18.11.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
libXvnc1-1.6.0-18.11.1
tigervnc-1.6.0-18.11.1
xorg-x11-Xvnc-1.6.0-18.11.1

Описание

In TigerVNC 1.7.1 (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:libXvnc1-1.6.0-18.11.1
SUSE Linux Enterprise Desktop 12 SP2:tigervnc-1.6.0-18.11.1
SUSE Linux Enterprise Desktop 12 SP2:xorg-x11-Xvnc-1.6.0-18.11.1
SUSE Linux Enterprise Server 12 SP2:libXvnc1-1.6.0-18.11.1

Ссылки

Описание

In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:libXvnc1-1.6.0-18.11.1
SUSE Linux Enterprise Desktop 12 SP2:tigervnc-1.6.0-18.11.1
SUSE Linux Enterprise Desktop 12 SP2:xorg-x11-Xvnc-1.6.0-18.11.1
SUSE Linux Enterprise Server 12 SP2:libXvnc1-1.6.0-18.11.1

Ссылки

Описание

In TigerVNC 1.7.1 (SSecurityPlain.cxx SSecurityPlain::processMsg), unauthenticated users can crash the server by sending long usernames.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:libXvnc1-1.6.0-18.11.1
SUSE Linux Enterprise Desktop 12 SP2:tigervnc-1.6.0-18.11.1
SUSE Linux Enterprise Desktop 12 SP2:xorg-x11-Xvnc-1.6.0-18.11.1
SUSE Linux Enterprise Server 12 SP2:libXvnc1-1.6.0-18.11.1

Ссылки

Описание

In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:libXvnc1-1.6.0-18.11.1
SUSE Linux Enterprise Desktop 12 SP2:tigervnc-1.6.0-18.11.1
SUSE Linux Enterprise Desktop 12 SP2:xorg-x11-Xvnc-1.6.0-18.11.1
SUSE Linux Enterprise Server 12 SP2:libXvnc1-1.6.0-18.11.1

Ссылки

Описание

In TigerVNC 1.7.1 (CConnection.cxx CConnection::CConnection), an unauthenticated client can cause a small memory leak in the server.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:libXvnc1-1.6.0-18.11.1
SUSE Linux Enterprise Desktop 12 SP2:tigervnc-1.6.0-18.11.1
SUSE Linux Enterprise Desktop 12 SP2:xorg-x11-Xvnc-1.6.0-18.11.1
SUSE Linux Enterprise Server 12 SP2:libXvnc1-1.6.0-18.11.1

Ссылки
Уязвимость SUSE-SU-2017:1094-1