Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 8: DLA-2014-1 Critical: vino DoS and Memory Leak

debian lts
Calendar Grey November 29, 2019
Dist Debian Esm H88
Enhance your Vino deployment to mitigate various security flaws such as Denial of Service and memory leaks on Debian platforms.
Several vulnerabilities have been identified in the VNC code of vino, a desktop sharing utility for the GNOME desktop environment

Summary

The vulnerabilities referenced below are issues that have originally been
reported against Debian source package libvncserver. The vino source
package in Debian ships a custom-patched and stripped down variant of
libvncserver, thus some of libvncserver's security fixes required porting
over.

CVE-2014-6053

The rfbProcessClientNormalMessage function in
libvncserver/rfbserver.c in LibVNCServer did not properly handle
attempts to send a large amount of ClientCutText data, which allowed
remote attackers to cause a denial of service (memory consumption or
daemon crash) via a crafted message that was processed by using a
single unchecked malloc.

CVE-2018-7225

An issue was discovered in LibVNCServer.
rfbProcessClientNormalMessage() in rfbserver.c did not sanitize
msg.cct.length, leading to access to uninitialized and potentially
sensitive data or possibly unspecified other impact (e.g., an integer
overflow) via specially crafted VNC packets.

CVE-2019-15681

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: vino
Version: 3.14.0-2+deb8u1
CVE ID: CVE-2014-6053 CVE-2018-7225 CVE-2019-15681
Debian Bug: 945784

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here