Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia: 2020-0207 Moderate: libvncserver Buffer Overflow Issue

mageia
Calendar Grey May 8, 2020
Dist Mageia Esm H88
The recent libvncserver updates address critical buffer and integer overflow security issues in Mageia 7. For further information, please continue reading.
Updated libvncserver packages fix security vulnerability: libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overf...

Summary

Updated libvncserver packages fix security vulnerability:
libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value (CVE-2019-20788).

References

- https://bugs.mageia.org/show_bug.cgi?id=26587

- https://www.cve.org/CVERecord?id=CVE-2019-20788

Resolution

SRPMS

- 7/core/libvncserver-0.9.12-2.3.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 08 May 2020
URL: https://advisories.mageia.org/MGASA-2020-0207.html
Type: security
CVE: CVE-2019-20788

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here