Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Oracle Linux 7 ELSA-2024-0006: Critical Tigervnc Out-Of-Bounds Fix

oracle
Calendar Grey January 3, 2024
Oracle Linux Logo Esm H88
An important security patch for Oracle Linux 7, ELSA-2024-0007 concerning tigervnc, addresses critical buffer overflow vulnerabilities.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Summary

[1.8.0-28.0.1] - Dropped xorg-CVE-2023-5367.patch, xorg-CVE-2023-6377.patch, and xorg-CVE-2023-6478.patch [1.8.0-28] - Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions Resolves: RHEL-18415 [1.8.0-27] - Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions Resolves: RHEL-18415 - CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty Resolves: RHEL-18427

SRPMs

https://oss.oracle.com:443/ol7/SRPMS-updates//tigervnc-1.8.0-28.0.1.el7_9.src.rpm

x86_64

tigervnc-1.8.0-28.0.1.el7_9.x86_64.rpm tigervnc-icons-1.8.0-28.0.1.el7_9.noarch.rpm tigervnc-license-1.8.0-28.0.1.el7_9.noarch.rpm tigervnc-server-1.8.0-28.0.1.el7_9.x86_64.rpm tigervnc-server-applet-1.8.0-28.0.1.el7_9.noarch.rpm tigervnc-server-minimal-1.8.0-28.0.1.el7_9.x86_64.rpm tigervnc-server-module-1.8.0-28.0.1.el7_9.x86_64.rpm

aarch64

Severity
critical
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2023-6377 CVE-2023-6478

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here