MGASA-2014-0466
Dashboard / Vulnerabilities / MGASA-2014-0466
MGASA-2014-0466
Summary: Updated kdenetwork4 packages fix security vulnerabilities in krfb
Details: A malicious VNC client can trigger multiple DoS conditions on the VNC server by advertising a large screen size, ClientCutText message length and/or a zero scaling factor parameter (CVE-2014-6053, CVE-2014-6054). A malicious VNC client can trigger multiple stack-based buffer overflows by passing a long file and directory names and/or attributes (FileTime) when using the file transfer message feature (CVE-2014-6055). The krfb package is built with a bundled copy of libvncserver.
References: https://advisories.mageia.org/MGASA-2014-0466.html, https://bugs.mageia.org/show_bug.cgi?id=14205, http://www.ocert.org/advisories/ocert-2014-007.html, https://www.kde.org/info/security/advisory-20140923-1.txt
Affected packages
Package
Name: kdenetwork4
Purl: pkg:rpm/mageia/kdenetwork4?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
