Updated libvncserver packages fix security vulnerability:
LibVNC contained a memory leak in VNC server code, which allowed an
attacker to read stack memory and could be abused for information
disclosure. Combined with another vulnerability, it could be used to
leak stack memory and bypass ASLR. This attack appeared to be
exploitable via network connectivity (CVE-2019-15681).
- https://bugs.mageia.org/show_bug.cgi?id=25788
- https://lists.debian.org/debian-lts-announce/2019/11/msg00032.html
- https://www.cve.org/CVERecord?id=CVE-2019-15681
- 7/core/libvncserver-0.9.12-2.1.mga7
Get the latest Linux and open source security news straight to your inbox.