RLSA-2021:1811
Dashboard / Vulnerabilities / RLSA-2021:1811
RLSA-2021:1811
Summary: Moderate: libvncserver security update
Details: LibVNCServer is a C library that enables you to implement VNC server functionality into own programs. Security Fix(es): * libvncserver: uninitialized memory contents are vulnerable to Information Leak (CVE-2018-21247) * libvncserver: buffer overflow in ConnectClientToUnixSock() (CVE-2019-20839) * libvncserver: libvncserver/rfbregion.c has a NULL pointer dereference (CVE-2020-14397) * libvncserver: libvncclient/rfbproto.c does not limit TextChat size (CVE-2020-14405) * libvncserver: libvncserver/rfbserver.c has a divide by zero which could result in DoS (CVE-2020-25708) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Rocky Linux 8.4 Release Notes linked from the References section.
References: https://errata.rockylinux.org/RLSA-2021:1811, https://bugzilla.redhat.com/show_bug.cgi?id=1849877, https://bugzilla.redhat.com/show_bug.cgi?id=1849886, https://bugzilla.redhat.com/show_bug.cgi?id=1860325, https://bugzilla.redhat.com/show_bug.cgi?id=1860344, https://bugzilla.redhat.com/show_bug.cgi?id=1896739
Affected packages
Package
Name: libvncserver
Purl: pkg:rpm/rocky-linux/libvncserver?distro=rocky-linux-8&epoch=0
Affected ranges
Type: ECOSYSTEM
Events:
