SUSE-SU-2018:0830-1
Dashboard / Vulnerabilities / SUSE-SU-2018:0830-1
SUSE-SU-2018:0830-1
Summary: Security update for LibVNCServer
Details: LibVNCServer was updated to fix two security issues. These security issues were fixed: - CVE-2018-7225: Missing input sanitization inside rfbserver.c rfbProcessClientNormalMessage() (bsc#1081493). - CVE-2016-9942: Heap-based buffer overflow in ultra.c allowed remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message with the Ultra type tile, such that the LZO payload decompressed length exceeds what is specified by the tile dimensions (bsc#1017712). - CVE-2016-9941: Heap-based buffer overflow in rfbproto.c allowed remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message containing a subrectangle outside of the client drawing area (bsc#1017711).
References: https://www.suse.com/support/update/announcement/2018/suse-su-20180830-1/, https://bugzilla.suse.com/1017711, https://bugzilla.suse.com/1017712, https://bugzilla.suse.com/1081493, https://www.suse.com/security/cve/CVE-2016-9941, https://www.suse.com/security/cve/CVE-2016-9942, https://www.suse.com/security/cve/CVE-2018-7225
Affected packages
Package
Name: LibVNCServer
Purl: pkg:rpm/suse/LibVNCServer&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
