MGASA-2019-0368 - Updated libvncserver packages fix security vulnerability

Publication date: 06 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0368.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-15681

Updated libvncserver packages fix security vulnerability:

LibVNC contained a memory leak in VNC server code, which allowed an
attacker to read stack memory and could be abused for information
disclosure. Combined with another vulnerability, it could be used to
leak stack memory and bypass ASLR. This attack appeared to be
exploitable via network connectivity (CVE-2019-15681).

References:
- https://bugs.mageia.org/show_bug.cgi?id=25788
- https://www.debian.org/lts/security/2019/dla-2014
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15681

SRPMS:
- 7/core/libvncserver-0.9.12-2.1.mga7

Mageia 2019-0368: libvncserver security update

Updated libvncserver packages fix security vulnerability: LibVNC contained a memory leak in VNC server code, which allowed an attacker to read stack memory and could be abused for...

Summary

Updated libvncserver packages fix security vulnerability:
LibVNC contained a memory leak in VNC server code, which allowed an attacker to read stack memory and could be abused for information disclosure. Combined with another vulnerability, it could be used to leak stack memory and bypass ASLR. This attack appeared to be exploitable via network connectivity (CVE-2019-15681).

References

- https://bugs.mageia.org/show_bug.cgi?id=25788

- https://www.debian.org/lts/security/2019/dla-2014

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15681

Resolution

MGASA-2019-0368 - Updated libvncserver packages fix security vulnerability

SRPMS

- 7/core/libvncserver-0.9.12-2.1.mga7

Severity
Publication date: 06 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0368.html
Type: security
CVE: CVE-2019-15681

Related News