SUSE-SU-2015:2110-1
Dashboard / Vulnerabilities / SUSE-SU-2015:2110-1
SUSE-SU-2015:2110-1
Summary: Security update for LibVNCServer
Details: The libvncserver package was updated to fix the following security issues: - bsc#897031: fix several security issues: * CVE-2014-6051: Integer overflow in MallocFrameBuffer() on client side. * CVE-2014-6052: Lack of malloc() return value checking on client side. * CVE-2014-6053: Server crash on a very large ClientCutText message. * CVE-2014-6054: Server crash when scaling factor is set to zero. * CVE-2014-6055: Multiple stack overflows in File Transfer feature.
References: https://www.suse.com/support/update/announcement/2015/suse-su-20152110-1/, https://bugzilla.suse.com/897031, https://www.suse.com/security/cve/CVE-2014-6051, https://www.suse.com/security/cve/CVE-2014-6052, https://www.suse.com/security/cve/CVE-2014-6053, https://www.suse.com/security/cve/CVE-2014-6054, https://www.suse.com/security/cve/CVE-2014-6055
Affected packages
Package
Name: LibVNCServer
Purl: pkg:rpm/suse/LibVNCServer&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
