Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2019:14235-1 Important: Tightvnc Code Execution and DoS Fixes

suse
Calendar Grey November 29, 2019
Dist Suse Esm H88
SUSE tightvnc upgrade addresses critical security flaws, bolstering system robustness and mitigating prospective threats.
An update that fixes four vulnerabilities is now available

Summary

This update for tightvnc fixes the following issues: - CVE-2019-15679: Fixed a heap buffer overflow in InitialiseRFBConnection which might lead to code execution (bsc#1155476). - CVE-2019-8287: Fixed a global buffer overflow in HandleCoRREBBPmay which might lead to code execution (bsc#1155472). - CVE-2019-15680: Fixed a null pointer dereference in HandleZlibBPP which could have led to denial of service (bsc#1155452). - CVE-2019-15678: Fixed a heap buffer overflow in rfbServerCutText handler (bsc#1155442). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-tightvnc-14235=1

References

#1155442 #1155452 #1155472 #1155476

Cross- CVE-2019-15678 CVE-2019-15679 CVE-2019-15680

CVE-2019-8287

Affected Products:

SUSE Linux Enterprise Server 11-SP4-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2019-15678.html

https://www.suse.com/security/cve/CVE-2019-15679.html

https://www.suse.com/security/cve/CVE-2019-15680.html

https://www.suse.com/security/cve/CVE-2019-8287.html

https://bugzilla.suse.com/1155442

https://bugzilla.suse.com/1155452

https://bugzilla.suse.com/1155472

https://bugzilla.suse.com/1155476

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:14235-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here