Several security issues were fixed in SSVNC.. =========================================================================Ubuntu Security Notice USN-4547-2 September 28, 2020 ssvnc vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Several security issues were fixed in SSVNC. Software Description: - ssvnc: Enhanced TightVNC viewer with SSL/SSH tunnel helper Details: It was discovered that the LibVNCClient vendored in SSVNC incorrectly handled certain packet lengths. A remote attacker could possibly use this issue to obtain sensitive information, cause a denial of service, or execute arbitrary code. (CVE-2018-20020, CVE-2018-20021, CVE-2018-20022, CVE-2018-2024) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: ssvnc 1.0.29-2+deb8u1build0.16.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4547-2 https://ubuntu.com/security/notices/USN-4547-1 CVE-2018-20020, CVE-2018-20021, CVE-2018-20022, CVE-2018-20024 Package Information: https://launchpad.net/ubuntu/+source/ssvnc/1.0.29-2+deb8u1build0.16.04.1 -- ubuntu-security-announce mailing list
Multiple vulnerabilities have been found in ssvnc, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202006-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: ssvnc: Multiple vulnerabilities Date: June 13, 2020 Bugs: #701820 ID: 202006-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in ssvnc, the worst of which could result in the arbitrary execution of code. Background ========= The Enhanced TightVNC Viewer, SSVNC, adds encryption security to VNC connections. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/ssvnc
Several vulnerabilities have been identified in the VNC code of ssvnc, an encryption-capable VNC client.. . Package : ssvnc Version : 1.0.29-2+deb8u1 CVE ID : CVE-2018-20020 CVE-2018-20021 CVE-2018-20022 CVE-2018-20024 Debian Bug : 945827 Several vulnerabilities have been identified in the VNC code of ssvnc, an encryption-capable VNC client.. The vulnerabilities referenced below are issues that have originally been reported against Debian source package libvncserver (which also ships the libvncclient shared library). The ssvnc source package in Debian ships a custom-patched, stripped down and outdated variant of libvncclient, thus some of libvncclient's security fixes required porting over. CVE-2018-20020 LibVNC contained heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code execution CVE-2018-20021 LibVNC contained a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM CVE-2018-20022 LibVNC contained multiple weaknesses CWE-665: Improper Initialization vulnerability in VNC client code that allowed attackers to read stack memory and could be abused for information disclosure. Combined with another vulnerability, it could be used to leak stack memory layout and in bypassing ASLR. CVE-2018-20024 LibVNC contained null pointer dereference in VNC client code that could result DoS. For Debian 8 "Jessie", these problems have been fixed in version 1.0.29-2+deb8u1. We recommend that you upgrade your ssvnc packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail:
Get the latest Linux and open source security news straight to your inbox.