=========================================================================Ubuntu Security Notice USN-3203-1
February 20, 2017

gtk-vnc vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

gtk-vnc could be made to crash or run programs if it received specially
crafted network traffic.

Software Description:
- gtk-vnc: VNC viewer widget

Details:

It was discovered that gtk-vnc incorrectly validated certain data. A
malicious server could use this issue to cause gtk-vnc to crash, resulting
in a denial of service, or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  libgtk-vnc-1.0-0                0.5.3-0ubuntu2.1
  libgtk-vnc-2.0-0                0.5.3-0ubuntu2.1
  libgvnc-1.0-0                   0.5.3-0ubuntu2.1

Ubuntu 12.04 LTS:
  libgtk-vnc-1.0-0                0.5.0-1ubuntu1.1
  libgtk-vnc-2.0-0                0.5.0-1ubuntu1.1
  libgvnc-1.0-0                   0.5.0-1ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-3203-1
  CVE-2017-5884, CVE-2017-5885

Package Information:
  https://launchpad.net/ubuntu/+source/gtk-vnc/0.5.3-0ubuntu2.1
  https://launchpad.net/ubuntu/+source/gtk-vnc/0.5.0-1ubuntu1.1


Ubuntu 3203-1: gtk-vnc vulnerabilities

February 20, 2017
gtk-vnc could be made to crash or run programs if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: libgtk-vnc-1.0-0 0.5.3-0ubuntu2.1 libgtk-vnc-2.0-0 0.5.3-0ubuntu2.1 libgvnc-1.0-0 0.5.3-0ubuntu2.1 Ubuntu 12.04 LTS: libgtk-vnc-1.0-0 0.5.0-1ubuntu1.1 libgtk-vnc-2.0-0 0.5.0-1ubuntu1.1 libgvnc-1.0-0 0.5.0-1ubuntu1.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3203-1

CVE-2017-5884, CVE-2017-5885

Severity
February 20, 2017

Package Information

https://launchpad.net/ubuntu/+source/gtk-vnc/0.5.3-0ubuntu2.1 https://launchpad.net/ubuntu/+source/gtk-vnc/0.5.0-1ubuntu1.1

Related News