Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 34: 2022-8b872b9214 Moderate: x11vnc Permission Vulnerability

fedora
Calendar Grey March 9, 2021
Dist Fedora Esm H88
This Fedora patch addresses vulnerability issues associated with trivial access to x11vnc shared memory segments, enhancing overall security.
This release fixes an insecure permissins of shared memory semgentes created by an x11vnc server

Summary

What WinVNC is to Windows x11vnc is to X Window System, i.e. a server which

serves the current X Window System desktop via RFB (VNC) protocol to the user.

Based on the ideas of x0rfbserver and on LibVNCServer it has evolved into

a versatile and productive while still easy to use program.

This release fixes an insecure permissins of shared memory semgentes created by

an x11vnc server. Previously the segments were readable and writable for any

local user. Now they are accessible only to the user who executed the x11vnc

server.

* Mon Mar 1 2021 Petr Pisar - 0.9.16-3

- Fix CVE-2020-29074 (insecure permissions on a shared memory) (bug #1933603)

[ 1 ] Bug #1933602 - CVE-2020-29074 x11vnc: insecure permissions on shm

https://bugzilla.redhat.com/show_bug.cgi?id=1933602

su -c 'dnf upgrade --advisory FEDORA-2021-c5b679877e' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 32
Version: 0.9.16
Release: 3.fc32
Summary: VNC server for the current X11 session

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here