Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Date: Wed, 11 Feb 2009 14:52:20 -0600 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Moderate: vnc on SL3.x, SL4.x, SL5.x i386/x86_64 Comments: To: " This email address is being protected from spambots. You need JavaScript enabled to view it. "Synopsis: Moderate: vnc security update Issue date: 2009-02-11 CVE Names: CVE-2008-4770 An insufficient input validation flaw was discovered in the VNC client application, vncviewer. If an attacker could convince a victim to connect to a malicious VNC server, or when an attacker was able to connect to vncviewer running in the "listen" mode, the attacker could cause the victim's vncviewer to crash or, possibly, execute arbitrary code. (CVE-2008-4770) For the update to take effect, all running instances of vncviewer must be restarted after the update is installed. SL 3.0.x SRPMS: vnc-4.0-0.beta4.1.8.src.rpm i386: vnc-4.0-0.beta4.1.8.i386.rpm vnc-server-4.0-0.beta4.1.8.i386.rpm x86_64: vnc-4.0-0.beta4.1.8.x86_64.rpm vnc-server-4.0-0.beta4.1.8.x86_64.rpm SL 4.x SRPMS: vnc-4.0-12.el4_7.1.src.rpm i386: vnc-4.0-12.el4_7.1.i386.rpm vnc-server-4.0-12.el4_7.1.i386.rpm x86_64: vnc-4.0-12.el4_7.1.x86_64.rpm vnc-server-4.0-12.el4_7.1.x86_64.rpm SL 5.x SRPMS: vnc-4.1.2-14.el5_3.1.src.rpm i386: vnc-4.1.2-14.el5_3.1.i386.rpm vnc-server-4.1.2-14.el5_3.1.i386.rpm x86_64: vnc-4.1.2-14.el5_3.1.x86_64.rpm vnc-server-4.1.2-14.el5_3.1.x86_64.rpm -Connie Sieh -Troy Dawson