USN-2365-1
Dashboard / Vulnerabilities / USN-2365-1
USN-2365-1
Summary: libvncserver vulnerabilities
Details: Nicolas Ruff discovered that LibVNCServer incorrectly handled memory when being advertised large screen sizes by the server. If a user were tricked into connecting to a malicious server, an attacker could use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2014-6051, CVE-2014-6052) Nicolas Ruff discovered that LibVNCServer incorrectly handled large ClientCutText messages. A remote attacker could use this issue to cause a server to crash, resulting in a denial of service. (CVE-2014-6053) Nicolas Ruff discovered that LibVNCServer incorrectly handled zero scaling factor values. A remote attacker could use this issue to cause a server to crash, resulting in a denial of service. (CVE-2014-6054) Nicolas Ruff discovered that LibVNCServer incorrectly handled memory in the file transfer feature. A remote attacker could use this issue to cause a server to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2014-6055)
References: https://ubuntu.com/security/notices/USN-2365-1, https://ubuntu.com/security/CVE-2014-6051, https://ubuntu.com/security/CVE-2014-6052, https://ubuntu.com/security/CVE-2014-6053, https://ubuntu.com/security/CVE-2014-6054, https://ubuntu.com/security/CVE-2014-6055
Affected packages
Package
Name: libvncserver
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu1.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
