Описание
Security update for tigervnc
This update for tigervnc provides the several fixes.
These security issues were fixed:
- CVE-2017-7392, CVE-2017-7396: Client can cause leak in VNC server (bsc#1031886)
- CVE-2017-7395: Authenticated VNC client can crash VNC server (bsc#1031877)
- CVE-2017-7394: Client can crash or block VNC server (bsc#1031879)
- CVE-2017-7393: Authenticated client can cause double free in VNC server (bsc#1031875)
- Prevent buffer overflow in VNC client, allowing for crashing the client (bnc#1032880)
These non-security issues were fixed:
- Prevent client disconnection caused by invalid cursor manipulation. (bsc#1024929, bsc#1031045)
- Readd index.vnc. (bsc#1026833)
- Crop operations to visible screen. (bnc#1032272)
Список пакетов
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP2
Ссылки
- Link for SUSE-SU-2017:1094-1
- E-Mail link for SUSE-SU-2017:1094-1
- SUSE Security Ratings
- SUSE Bug 1024929
- SUSE Bug 1026833
- SUSE Bug 1031045
- SUSE Bug 1031875
- SUSE Bug 1031877
- SUSE Bug 1031879
- SUSE Bug 1031886
- SUSE Bug 1032272
- SUSE Bug 1032880
- SUSE CVE CVE-2017-7392 page
- SUSE CVE CVE-2017-7393 page
- SUSE CVE CVE-2017-7394 page
- SUSE CVE CVE-2017-7395 page
- SUSE CVE CVE-2017-7396 page
Описание
In TigerVNC 1.7.1 (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server.
Затронутые продукты
Ссылки
- CVE-2017-7392
- SUSE Bug 1031886
Описание
In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution.
Затронутые продукты
Ссылки
- CVE-2017-7393
- SUSE Bug 1031875
- SUSE Bug 1031879
Описание
In TigerVNC 1.7.1 (SSecurityPlain.cxx SSecurityPlain::processMsg), unauthenticated users can crash the server by sending long usernames.
Затронутые продукты
Ссылки
- CVE-2017-7394
- SUSE Bug 1031879
Описание
In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server.
Затронутые продукты
Ссылки
- CVE-2017-7395
- SUSE Bug 1031877
Описание
In TigerVNC 1.7.1 (CConnection.cxx CConnection::CConnection), an unauthenticated client can cause a small memory leak in the server.
Затронутые продукты
Ссылки
- CVE-2017-7396
- SUSE Bug 1031886