Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 7: 2020-0042 Moderate: Tigervnc Client And Server Issues

mageia
Calendar Grey January 19, 2020
Dist Mageia Esm H88
Recent updates to tigervnc packages tackle security vulnerabilities that could enable unauthorized control by malicious actors. Learn more about the specifics of these fixes.
Updated tigervnc packages fix security vulnerabilities: The tigervnc package has been updated to version 1.10.1 to fix multiple unspecified security issues

Summary

Updated tigervnc packages fix security vulnerabilities:
The tigervnc package has been updated to version 1.10.1 to fix multiple unspecified security issues. These issues affect both the client and server and could theoretically allow an malicious peer to take control over the software on the other side. No working exploit is known at this time, and the issues require the peer to first be authenticated (CVE-2019-15691, CVE-2019-15692, CVE-2019-15693, CVE-2019-15694, CVE-2019-15695).

References

- https://bugs.mageia.org/show_bug.cgi?id=25917

- https://github.com/TigerVNC/tigervnc/releases/tag/v1.10.1

- https://www.openwall.com/lists/oss-security/2019/12/20/2

- https://www.cve.org/CVERecord?id=CVE-2019-15691

- https://www.cve.org/CVERecord?id=CVE-2019-15692

- https://www.cve.org/CVERecord?id=CVE-2019-15693

- https://www.cve.org/CVERecord?id=CVE-2019-15694

- https://www.cve.org/CVERecord?id=CVE-2019-15695

Resolution

SRPMS

- 7/core/tigervnc-1.10.1-1.mga7

Publication date: 19 Jan 2020
URL: https://advisories.mageia.org/MGASA-2020-0042.html
Type: security
CVE: CVE-2019-15691, CVE-2019-15692, CVE-2019-15693, CVE-2019-15694, CVE-2019-15695

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here