Date: Wed, 11 Feb 2009 14:52:20 -0600 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Moderate: vnc on SL3.x, SL4.x, SL5.x i386/x86_64 Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Moderate: vnc security update Issue date: 2009-02-11 CVE Names: CVE-2008-4770 An insufficient input validation flaw was discovered in the VNC client application, vncviewer. If an attacker could convince a victim to connect to a malicious VNC server, or when an attacker was able to connect to vncviewer running in the "listen" mode, the attacker could cause the victim's vncviewer to crash or, possibly, execute arbitrary code. (CVE-2008-4770) For the update to take effect, all running instances of vncviewer must be restarted after the update is installed. SL 3.0.x SRPMS: vnc-4.0-0.beta4.1.8.src.rpm i386: vnc-4.0-0.beta4.1.8.i386.rpm vnc-server-4.0-0.beta4.1.8.i386.rpm x86_64: vnc-4.0-0.beta4.1.8.x86_64.rpm vnc-server-4.0-0.beta4.1.8.x86_64.rpm SL 4.x SRPMS: vnc-4.0-12.el4_7.1.src.rpm i386: vnc-4.0-12.el4_7.1.i386.rpm vnc-server-4.0-12.el4_7.1.i386.rpm x86_64: vnc-4.0-12.el4_7.1.x86_64.rpm vnc-server-4.0-12.el4_7.1.x86_64.rpm SL 5.x SRPMS: vnc-4.1.2-14.el5_3.1.src.rpm i386: vnc-4.1.2-14.el5_3.1.i386.rpm vnc-server-4.1.2-14.el5_3.1.i386.rpm x86_64: vnc-4.1.2-14.el5_3.1.x86_64.rpm vnc-server-4.1.2-14.el5_3.1.x86_64.rpm -Connie Sieh -Troy Dawson