Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 5 articles for you...
89

Fedora 36 - 2023-c41e8f24bb Moderate: Tigervnc Use-After-Free Elevation

Tigervnc 1.13.1 update. CVE-2023-0494 tigervnc: xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-c41e8f24bb 2023-03-18 05:00:58.357197 --------------------------------------------------------------------------------Name : tigervnc Product : Fedora 36 Version : 1.13.1 Release : 1.fc36 URL : https://tigervnc.org/ Summary : A TigerVNC remote display system Description : Virtual Network Computing (VNC) is a remote display system which allows you to view a computing 'desktop' environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. This package contains a client which will allow you to connect to other desktops running a VNC server. --------------------------------------------------------------------------------Update Information: Tigervnc 1.13.1 update. CVE-2023-0494 tigervnc: xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation --------------------------------------------------------------------------------ChangeLog: * Wed Mar 1 2023 Jan Grulich - 1.13.1-1 - 1.13.1 * Tue Feb 21 2023 Jan Grulich - 1.13.0-3 - vncsession: allow to create .vnc directory * Wed Feb 15 2023 Jan Grulich - 1.13.0-2 - Backport: Sanity check when cleaning up keymap changes * Tue Feb 7 2023 Jan Grulich - 1.13.0-1 - 1.13.0 - CVE-2023-0494 * Tue Jan 31 2023 Jan Grulich - 1.12.0-9 - migrated to SPDX license * Sat Jan 21 2023 Fedora Release Engineering - 1.12.0-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Sat Jul 23 2022 Fedora Release Engineering - 1.12.0-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2165995 - CVE-2023-0494xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation https://bugzilla.redhat.com/show_bug.cgi?id=2165995 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-c41e8f24bb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Tigervnc 1.13.1 for Fedora 36 resolves CVE-2023-0494, which could allow privilege escalation due to use-after-free vulnerabilities.. Tigervnc Update,Fedora Security Update,Remote Display System Update. . LinuxSecurity.com Team

Calendar%202 Mar 18, 2023 Fedora
89

Fedora 36: 2023-1ebf4507df Critical: Xwayland Privilege Elevation Issue

xwayland 22.1.8 - Security fix for CVE-2023-0494. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-1ebf4507df 2023-02-22 11:06:32.699844 --------------------------------------------------------------------------------Name : xorg-x11-server-Xwayland Product : Fedora 36 Version : 22.1.8 Release : 1.fc36 URL : https://www.x.org/wiki/ Summary : Xwayland Description : Xwayland is an X server for running X clients under Wayland. --------------------------------------------------------------------------------Update Information: xwayland 22.1.8 - Security fix for CVE-2023-0494 --------------------------------------------------------------------------------ChangeLog: * Tue Feb 7 2023 Olivier Fourdan - 22.1.8-1 - xwayland 22.1.8 Fixes CVE-2023-0494 (#2165995, #2167566, #2167734) * Sun Jan 29 2023 Stefan Bluhm - 22.1.7-4 - Updated conditional Fedora statement. * Thu Jan 19 2023 Olivier Fourdan - 22.1.7-3 - Use the recommended way to apply conditional patches without conditionalizing the sources (for byte-swapped clients). * Tue Jan 17 2023 Olivier Fourdan - 22.1.7-2 - Disallow byte-swapped clients on Fedora 38 and above (#2159489) --------------------------------------------------------------------------------References: [ 1 ] Bug #2165995 - CVE-2023-0494 xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation https://bugzilla.redhat.com/show_bug.cgi?id=2165995 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-1ebf4507df' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora releases a security patch for Xwayland, resolving vulnerability CVE-2023-0494, complete with upgrade guidelines.. Xwayland Update, Critical Fix, Fedora Security, Privilege Escalation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 22, 2023 Critical Fedora
89

Fedora 37: FEDORA-2023-83b2d37c6a moderate: xwayland privilege elevation

xwayland 22.1.8 - Security fix for CVE-2023-0494. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-83b2d37c6a 2023-02-12 00:37:30.247842 --------------------------------------------------------------------------------Name : xorg-x11-server-Xwayland Product : Fedora 37 Version : 22.1.8 Release : 1.fc37 URL : https://www.x.org/wiki/ Summary : Xwayland Description : Xwayland is an X server for running X clients under Wayland. --------------------------------------------------------------------------------Update Information: xwayland 22.1.8 - Security fix for CVE-2023-0494 --------------------------------------------------------------------------------ChangeLog: * Tue Feb 7 2023 Olivier Fourdan - 22.1.8-1 - xwayland 22.1.8 Fixes CVE-2023-0494 (#2165995, #2167566, #2167734) * Sun Jan 29 2023 Stefan Bluhm - 22.1.7-4 - Updated conditional Fedora statement. * Thu Jan 19 2023 Olivier Fourdan - 22.1.7-3 - Use the recommended way to apply conditional patches without conditionalizing the sources (for byte-swapped clients). * Tue Jan 17 2023 Olivier Fourdan - 22.1.7-2 - Disallow byte-swapped clients on Fedora 38 and above (#2159489) --------------------------------------------------------------------------------References: [ 1 ] Bug #2165995 - CVE-2023-0494 xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation https://bugzilla.redhat.com/show_bug.cgi?id=2165995 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-83b2d37c6a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Xwayland 22.1.9 now available for Fedora 37 tackles CVE-2023-0495 privilege escalation vulnerability. Users should update promptly.. xwayland, security patch, Fedora update, privilege elevation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 12, 2023 Important Fedora
200

Scientific Linux 7: SLSA-2023-0675-1 Important: Tigervnc Elevation Fix

xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation (CVE-2023-0494) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 tigervnc-1.8.0-24.el7_9.x86_64.rpm tigervnc-debuginfo-1.8.0-24.el7_9.x86_64.rpm tigervnc-server-1.8.0-24.el7_9.x86_64.rpm [More...]. Synopsis: Important: tigervnc and xorg-x11-server security update Advisory ID: SLSA-2023:0675-1 Issue Date: 2023-02-09 CVE Numbers: CVE-2023-0494 -- X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon. Security Fix(es): * xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation (CVE-2023-0494) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 tigervnc-1.8.0-24.el7_9.x86_64.rpm tigervnc-debuginfo-1.8.0-24.el7_9.x86_64.rpm tigervnc-server-1.8.0-24.el7_9.x86_64.rpm tigervnc-server-minimal-1.8.0-24.el7_9.x86_64.rpm xorg-x11-server-Xephyr-1.20.4-22.el7_9.x86_64.rpm xorg-x11-server-Xorg-1.20.4-22.el7_9.x86_64.rpm xorg-x11-server-common-1.20.4-22.el7_9.x86_64.rpm xorg-x11-server-debuginfo-1.20.4-22.el7_9.x86_64.rpm tigervnc-server-module-1.8.0-24.el7_9.x86_64.rpm xorg-x11-server-Xdmx-1.20.4-22.el7_9.x86_64.rpm xorg-x11-server-Xnest-1.20.4-22.el7_9.x86_64.rpm xorg-x11-server-Xvfb-1.20.4-22.el7_9.x86_64.rpm xorg-x11-server-Xwayland-1.20.4-22.el7_9.x86_64.rpm xorg-x11-server-debuginfo-1.20.4-22.el7_9.i686.rpm xorg-x11-server-devel-1.20.4-22.el7_9.i686.rpm xorg-x11-server-devel-1.20.4-22.el7_9.x86_64.rpm noarch tigervnc-icons-1.8.0-24.el7_9.noarch.rpm tigervnc-license-1.8.0-24.el7_9.noarch.rpm tigervnc-server-applet-1.8.0-24.el7_9.noarch.rpm xorg-x11-server-source-1.20.4-22.el7_9.noarch.rpm - Scientific Linux Development Team . Important software patch addresses security loophole allowing higher access levels in tigervnc and xorg-x11-server for Scientific Linux 7.. tigervnc security patch, xorg-x11 update, Scientific Linux patch, SL7 security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 09, 2023 Important Scientific Linux
217

Oracle Linux 8: ELSA-2023-0662 Critical Update for Tigervnc Server

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-0662 https://linux.oracle.com/errata/ELSA-2023-0662.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: tigervnc-1.12.0-9.el8_7.1.x86_64.rpm tigervnc-icons-1.12.0-9.el8_7.1.noarch.rpm tigervnc-license-1.12.0-9.el8_7.1.noarch.rpm tigervnc-selinux-1.12.0-9.el8_7.1.noarch.rpm tigervnc-server-1.12.0-9.el8_7.1.x86_64.rpm tigervnc-server-minimal-1.12.0-9.el8_7.1.x86_64.rpm tigervnc-server-module-1.12.0-9.el8_7.1.x86_64.rpm aarch64: tigervnc-1.12.0-9.el8_7.1.aarch64.rpm tigervnc-icons-1.12.0-9.el8_7.1.noarch.rpm tigervnc-license-1.12.0-9.el8_7.1.noarch.rpm tigervnc-selinux-1.12.0-9.el8_7.1.noarch.rpm tigervnc-server-1.12.0-9.el8_7.1.aarch64.rpm tigervnc-server-minimal-1.12.0-9.el8_7.1.aarch64.rpm tigervnc-server-module-1.12.0-9.el8_7.1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//tigervnc-1.12.0-9.el8_7.1.src.rpm Related CVEs: CVE-2023-0494 Description of changes: [1.12.0-9] - xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation Resolves: bz#2167057 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . CentOS Stream ELSA-2023-0789 offers patches for OpenSSH targeting security vulnerabilities. Discover further details.. Oracle Linux Update,Tigervnc Security Patch,ELSA-2023-0662. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 08, 2023 Critical Oracle
98

Red Hat 8.1 RHSA-2023:0665-01 Important Tigervnc Security Patch

An update for tigervnc is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: tigervnc security update Advisory ID: RHSA-2023:0665-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0665 Issue date: 2023-02-08 CVE Names: CVE-2023-0494 ==================================================================== 1. Summary: An update for tigervnc is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream E4S (v. 8.1) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Virtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients. Security Fix(es): * xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation (CVE-2023-0494) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2165995 - CVE-2023-0494 xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation 6. Package List: Red Hat Enterprise Linux AppStream E4S (v.8.1): Source: tigervnc-1.9.0-16.el8_1.1.src.rpm aarch64: tigervnc-1.9.0-16.el8_1.1.aarch64.rpm tigervnc-debuginfo-1.9.0-16.el8_1.1.aarch64.rpm tigervnc-debugsource-1.9.0-16.el8_1.1.aarch64.rpm tigervnc-server-1.9.0-16.el8_1.1.aarch64.rpm tigervnc-server-debuginfo-1.9.0-16.el8_1.1.aarch64.rpm tigervnc-server-minimal-1.9.0-16.el8_1.1.aarch64.rpm tigervnc-server-minimal-debuginfo-1.9.0-16.el8_1.1.aarch64.rpm tigervnc-server-module-1.9.0-16.el8_1.1.aarch64.rpm tigervnc-server-module-debuginfo-1.9.0-16.el8_1.1.aarch64.rpm noarch: tigervnc-icons-1.9.0-16.el8_1.1.noarch.rpm tigervnc-license-1.9.0-16.el8_1.1.noarch.rpm tigervnc-server-applet-1.9.0-16.el8_1.1.noarch.rpm ppc64le: tigervnc-1.9.0-16.el8_1.1.ppc64le.rpm tigervnc-debuginfo-1.9.0-16.el8_1.1.ppc64le.rpm tigervnc-debugsource-1.9.0-16.el8_1.1.ppc64le.rpm tigervnc-server-1.9.0-16.el8_1.1.ppc64le.rpm tigervnc-server-debuginfo-1.9.0-16.el8_1.1.ppc64le.rpm tigervnc-server-minimal-1.9.0-16.el8_1.1.ppc64le.rpm tigervnc-server-minimal-debuginfo-1.9.0-16.el8_1.1.ppc64le.rpm tigervnc-server-module-1.9.0-16.el8_1.1.ppc64le.rpm tigervnc-server-module-debuginfo-1.9.0-16.el8_1.1.ppc64le.rpm s390x: tigervnc-1.9.0-16.el8_1.1.s390x.rpm tigervnc-debuginfo-1.9.0-16.el8_1.1.s390x.rpm tigervnc-debugsource-1.9.0-16.el8_1.1.s390x.rpm tigervnc-server-1.9.0-16.el8_1.1.s390x.rpm tigervnc-server-debuginfo-1.9.0-16.el8_1.1.s390x.rpm tigervnc-server-minimal-1.9.0-16.el8_1.1.s390x.rpm tigervnc-server-minimal-debuginfo-1.9.0-16.el8_1.1.s390x.rpm x86_64: tigervnc-1.9.0-16.el8_1.1.x86_64.rpm tigervnc-debuginfo-1.9.0-16.el8_1.1.x86_64.rpm tigervnc-debugsource-1.9.0-16.el8_1.1.x86_64.rpm tigervnc-server-1.9.0-16.el8_1.1.x86_64.rpm tigervnc-server-debuginfo-1.9.0-16.el8_1.1.x86_64.rpm tigervnc-server-minimal-1.9.0-16.el8_1.1.x86_64.rpm tigervnc-server-minimal-debuginfo-1.9.0-16.el8_1.1.x86_64.rpm tigervnc-server-module-1.9.0-16.el8_1.1.x86_64.rpm tigervnc-server-module-debuginfo-1.9.0-16.el8_1.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how toverify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-0494 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY+O++NzjgjWX9erEAQhF/Q/+MQMIDnSwpYPTjS/n7paFV7ifClBDd44n iHN1JJ3SNACmAgw/lxvs4lyXnvMaFbvXvZGMn8dmz4tpakQMTuJJWH0FSnCiB4Mp R+2SqyG1LLSLmT8WUo5653SMkGjoVgEwWTK88GPRa3lNOWoywq4DSs5062m2SxTc WFZqpjodP8La3OHrTwpBcfRrSQFD/UX0/GUINfiZIayu6yhc9u+dvhBPaJh/de1o zmXeW/LZag8Pb4k9PWRoTMpCxI4R+lEe83iAwmFTbKbzOXzqFZF79XVYUWt1DOzM BwEdoZxybD5xx1gz7FrEbWrv/aQ9FdidtvLRzLA09nqsLqmDI6Y/k49gTtlnC4J4 oMM049jrJMTx0L1kM5MDybpS6EZQzDu68g05ry3L1/KFGRN0IdBUo97k596oZ+WB YYh/xoleixN5c9eSpxRzIuuHFOce4fiAyJ1CLpMIejPfoeh6RsptSPrVywmlCN+1 0p0AOcB7MWmwOVjdYdPfWSVrRGcWf1lxOsL/H9UmaODdissA0ceUPHEaTgunTwyd U6HtTDq9bk+OSJiypVKPX8eiC4j/MWPPLyO72usDW0BO0htEOXWnFUSD69hBsSZ8 cpU9psvBGMAhW583gsd9SWIWGBaVequGeIJ4UQiXRDn6h4+wkjYqH6Y7fYsD/87g Mtgy3h9fCqc=FCNE -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A significant patch for tigervnc on CentOS has been released addressing potential escalated privileges.. tigervnc Update, Red Hat Security Patch, Virtual Network Computing. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 08, 2023 Important Red Hat
98

Red Hat Enterprise 8 RHSA-2023-0662 Important: Tigervnc Privilege Elevation

An update for tigervnc is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: tigervnc security update Advisory ID: RHSA-2023:0662-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0662 Issue date: 2023-02-08 CVE Names: CVE-2023-0494 ==================================================================== 1. Summary: An update for tigervnc is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Virtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients. Security Fix(es): * xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation (CVE-2023-0494) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2165995 - CVE-2023-0494 xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation 6. Package List: Red Hat Enterprise Linux AppStream (v.8): Source: tigervnc-1.12.0-9.el8_7.1.src.rpm aarch64: tigervnc-1.12.0-9.el8_7.1.aarch64.rpm tigervnc-debuginfo-1.12.0-9.el8_7.1.aarch64.rpm tigervnc-debugsource-1.12.0-9.el8_7.1.aarch64.rpm tigervnc-server-1.12.0-9.el8_7.1.aarch64.rpm tigervnc-server-debuginfo-1.12.0-9.el8_7.1.aarch64.rpm tigervnc-server-minimal-1.12.0-9.el8_7.1.aarch64.rpm tigervnc-server-minimal-debuginfo-1.12.0-9.el8_7.1.aarch64.rpm tigervnc-server-module-1.12.0-9.el8_7.1.aarch64.rpm tigervnc-server-module-debuginfo-1.12.0-9.el8_7.1.aarch64.rpm noarch: tigervnc-icons-1.12.0-9.el8_7.1.noarch.rpm tigervnc-license-1.12.0-9.el8_7.1.noarch.rpm tigervnc-selinux-1.12.0-9.el8_7.1.noarch.rpm ppc64le: tigervnc-1.12.0-9.el8_7.1.ppc64le.rpm tigervnc-debuginfo-1.12.0-9.el8_7.1.ppc64le.rpm tigervnc-debugsource-1.12.0-9.el8_7.1.ppc64le.rpm tigervnc-server-1.12.0-9.el8_7.1.ppc64le.rpm tigervnc-server-debuginfo-1.12.0-9.el8_7.1.ppc64le.rpm tigervnc-server-minimal-1.12.0-9.el8_7.1.ppc64le.rpm tigervnc-server-minimal-debuginfo-1.12.0-9.el8_7.1.ppc64le.rpm tigervnc-server-module-1.12.0-9.el8_7.1.ppc64le.rpm tigervnc-server-module-debuginfo-1.12.0-9.el8_7.1.ppc64le.rpm s390x: tigervnc-1.12.0-9.el8_7.1.s390x.rpm tigervnc-debuginfo-1.12.0-9.el8_7.1.s390x.rpm tigervnc-debugsource-1.12.0-9.el8_7.1.s390x.rpm tigervnc-server-1.12.0-9.el8_7.1.s390x.rpm tigervnc-server-debuginfo-1.12.0-9.el8_7.1.s390x.rpm tigervnc-server-minimal-1.12.0-9.el8_7.1.s390x.rpm tigervnc-server-minimal-debuginfo-1.12.0-9.el8_7.1.s390x.rpm tigervnc-server-module-1.12.0-9.el8_7.1.s390x.rpm tigervnc-server-module-debuginfo-1.12.0-9.el8_7.1.s390x.rpm x86_64: tigervnc-1.12.0-9.el8_7.1.x86_64.rpm tigervnc-debuginfo-1.12.0-9.el8_7.1.x86_64.rpm tigervnc-debugsource-1.12.0-9.el8_7.1.x86_64.rpm tigervnc-server-1.12.0-9.el8_7.1.x86_64.rpm tigervnc-server-debuginfo-1.12.0-9.el8_7.1.x86_64.rpm tigervnc-server-minimal-1.12.0-9.el8_7.1.x86_64.rpm tigervnc-server-minimal-debuginfo-1.12.0-9.el8_7.1.x86_64.rpm tigervnc-server-module-1.12.0-9.el8_7.1.x86_64.rpm tigervnc-server-module-debuginfo-1.12.0-9.el8_7.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-0494 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY+O+9dzjgjWX9erEAQh3TA/+Ml6Y6q4JAQU3ehMR0ofnHwUlTy0Hsj8j 2wetFd2j414J0cZ1RVtMAgDpVO4g0e1jEii+r6/fvO6lkIzXMF5WQy+lnJl5OJgw 2v+EYHko7Knlo0pn8+b5TY4ZhplACnABhyb5WiVAT/ks25bq+tUUH/wcNoMPjh4O vod3cEtdPZyjqR1YLoH+udjFrA+fr//ccDiSD/IfW1PXWN1PRObtXcwGd4PmyTTn cuyXMXGx1mrClganlrP99HIrroOV4llrgTRGNZ04OFDzDlxJB3bgYJV5lZYaTb4W JcSL21c5Fx75aKgbtxBs7Ugy5bUJcOECij+CWxEAA3JPlbSBBIvTWpUv86gubyFE spadJWVnts1kh3yYWB/KHP3jqQPyu8u/EoGT8nVAiwL6wFUlmaq+YnpUzy3qs7Hk ae2Jzz7SzYVAVKlVWQGRpD0iqye8hfQpJ06NvpOVBvmFTtGOjNyCsaxUDl5amKGO koJ7mFRzczCiP3MuGtHUPWZGVsQdEt/hbcKL7QLymyHPcgQpti42fn0LrBq8eaAp KTak9vHmC8FXGH05Xfsrd242yT6sbb/4NU04YK2AzIlkAIjP0yTeOyaEXYR1d2Qf 8d5Jr4MHsPhlr7QBfVmeLibRC6U2PZuCpByy19iiREkWDhO6u5uRH5aQkOBs00Cd by/LOkyPPHg=ADJj -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Explore the key features of the recent tigervnc security patch for Red Hat Enterprise Linux and understand its possible ramifications.. Red Hat Advisory, Tigervnc Security Update, Linux Security Fix, Remote Access Vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 08, 2023 Important Red Hat
98

Red Hat: RHSA-2023-0664-01 Important: Tigervnc Privilege Elevation

An update for tigervnc is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: tigervnc security update Advisory ID: RHSA-2023:0664-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0664 Issue date: 2023-02-08 CVE Names: CVE-2023-0494 ==================================================================== 1. Summary: An update for tigervnc is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.8.4) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Virtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients. Security Fix(es): * xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation (CVE-2023-0494) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5.Bugs fixed (https://bugzilla.redhat.com/): 2165995 - CVE-2023-0494 xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation 6. Package List: Red Hat Enterprise Linux AppStream EUS(v.8.4): Source: tigervnc-1.11.0-8.el8_4.1.src.rpm aarch64: tigervnc-1.11.0-8.el8_4.1.aarch64.rpm tigervnc-debuginfo-1.11.0-8.el8_4.1.aarch64.rpm tigervnc-debugsource-1.11.0-8.el8_4.1.aarch64.rpm tigervnc-server-1.11.0-8.el8_4.1.aarch64.rpm tigervnc-server-debuginfo-1.11.0-8.el8_4.1.aarch64.rpm tigervnc-server-minimal-1.11.0-8.el8_4.1.aarch64.rpm tigervnc-server-minimal-debuginfo-1.11.0-8.el8_4.1.aarch64.rpm tigervnc-server-module-1.11.0-8.el8_4.1.aarch64.rpm tigervnc-server-module-debuginfo-1.11.0-8.el8_4.1.aarch64.rpm noarch: tigervnc-icons-1.11.0-8.el8_4.1.noarch.rpm tigervnc-license-1.11.0-8.el8_4.1.noarch.rpm tigervnc-selinux-1.11.0-8.el8_4.1.noarch.rpm ppc64le: tigervnc-1.11.0-8.el8_4.1.ppc64le.rpm tigervnc-debuginfo-1.11.0-8.el8_4.1.ppc64le.rpm tigervnc-debugsource-1.11.0-8.el8_4.1.ppc64le.rpm tigervnc-server-1.11.0-8.el8_4.1.ppc64le.rpm tigervnc-server-debuginfo-1.11.0-8.el8_4.1.ppc64le.rpm tigervnc-server-minimal-1.11.0-8.el8_4.1.ppc64le.rpm tigervnc-server-minimal-debuginfo-1.11.0-8.el8_4.1.ppc64le.rpm tigervnc-server-module-1.11.0-8.el8_4.1.ppc64le.rpm tigervnc-server-module-debuginfo-1.11.0-8.el8_4.1.ppc64le.rpm s390x: tigervnc-1.11.0-8.el8_4.1.s390x.rpm tigervnc-debuginfo-1.11.0-8.el8_4.1.s390x.rpm tigervnc-debugsource-1.11.0-8.el8_4.1.s390x.rpm tigervnc-server-1.11.0-8.el8_4.1.s390x.rpm tigervnc-server-debuginfo-1.11.0-8.el8_4.1.s390x.rpm tigervnc-server-minimal-1.11.0-8.el8_4.1.s390x.rpm tigervnc-server-minimal-debuginfo-1.11.0-8.el8_4.1.s390x.rpm tigervnc-server-module-1.11.0-8.el8_4.1.s390x.rpm tigervnc-server-module-debuginfo-1.11.0-8.el8_4.1.s390x.rpm x86_64: tigervnc-1.11.0-8.el8_4.1.x86_64.rpm tigervnc-debuginfo-1.11.0-8.el8_4.1.x86_64.rpm tigervnc-debugsource-1.11.0-8.el8_4.1.x86_64.rpm tigervnc-server-1.11.0-8.el8_4.1.x86_64.rpm tigervnc-server-debuginfo-1.11.0-8.el8_4.1.x86_64.rpm tigervnc-server-minimal-1.11.0-8.el8_4.1.x86_64.rpm tigervnc-server-minimal-debuginfo-1.11.0-8.el8_4.1.x86_64.rpm tigervnc-server-module-1.11.0-8.el8_4.1.x86_64.rpm tigervnc-server-module-debuginfo-1.11.0-8.el8_4.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-0494 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY+O+8tzjgjWX9erEAQiZ1A/+KID5lPujRFTRtprlpv5qmW9sp4HESuJL J5jA8mR3EubAmMRwcY2PnUvCUP9LrfXUqR+hcUVKvU9udHeySgGxXNdvznVlBQUk pr761nSaQsiexMrg2p2ucBORTR8PM871DNcqpbbrupAcMIOpiHnWaOyUgFHXLaRW pVzv5JJCPFwH6/KeWIr47wgIUDGeVWJsvLk43poeOVlFwSENCWZ1DvaKip5DjKMc nb9ftgR2PHCGp5K+myNgqLsSXEQDU8xzMMqPqwBZFUPfOzIaDzF+mdrL5VEeSLsE 9zvT+0uTotANwBJS8RYUk+x9xOYZffvSAQN6m/LQ7veBSjElgoYC/YyUvY5A7lJg y9Jp5BhTUJoeHBz8GDsxC+Pq+7BrGkmM2HYXlbY8SlbPlU7rREQb1AafHtLTGZkl T0MIiY7b3SCNNXX1DncLCz7+Cz84QyamhinikVf2GEpxbJk2aLZJR4rjHIzJorIt kC7b7641/r1hamLSr3zmyKSSBf7PI/yaDTzlyyqsZEtJd6HsPHLZkh6t101IdnOb A6j604gSt6PoKFqOuf4RlvSUFD2MrU6UFz60gN2KEzfT9FbNSsuqxOAjX8LsY069 vAWAmINWOQW3/7Dvnf8iG4zAoajE/s4FNWk1Is0AYq59jvb4aah7mAyRT0y6F+2+ bK5z5JPq30E=NKII -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Keep abreast of essential updates via this Red Hat notice regarding the significant tigervnc vulnerability patch, emphasizing the CVE-2023-0494 threat.. Tigervnc Update, Red Hat Security, Important Advisory, Remote Access Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 08, 2023 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200