MGASA-2018-0198
Dashboard / Vulnerabilities / MGASA-2018-0198
Summary: Updated libvncserver packages fix security vulnerability
Details: An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets (CVE-2018-7225).
References: https://advisories.mageia.org/MGASA-2018-0198.html, https://bugs.mageia.org/show_bug.cgi?id=22847, https://lists.fedoraproject.org/archives/list/[email protected]/thread/YYNK6ZTW4QSUNWBL3YCZXRC3QMHW7FZK/
Affected packages
Package
Name: libvncserver
Purl: pkg:rpm/mageia/libvncserver?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
