Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Mageia: 2019-0368 Moderate: LibVNC Server Memory Leak Exploit

mageia
Calendar Grey December 6, 2019
Dist Mageia Esm H88
Recent libvncserver updates fix a security flaw that leads to a memory leak, potentially enabling an attacker to access sensitive stack memory.
Updated libvncserver packages fix security vulnerability: LibVNC contained a memory leak in VNC server code, which allowed an attacker to read stack memory and could be abused for...

Summary

Updated libvncserver packages fix security vulnerability:
LibVNC contained a memory leak in VNC server code, which allowed an attacker to read stack memory and could be abused for information disclosure. Combined with another vulnerability, it could be used to leak stack memory and bypass ASLR. This attack appeared to be exploitable via network connectivity (CVE-2019-15681).

References

- https://bugs.mageia.org/show_bug.cgi?id=25788

- https://lists.debian.org/debian-lts-announce/2019/11/msg00032.html

- https://www.cve.org/CVERecord?id=CVE-2019-15681

Resolution

SRPMS

- 7/core/libvncserver-0.9.12-2.1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 06 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0368.html
Type: security
CVE: CVE-2019-15681

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here