Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
197

Debian 10: DLA-3608-1 Moderate: Vinagre RDP Crash Severity

It has been found that the update of freerdp2 (see DLA-3606-1) exposed a bug in vinagre, which causes crashes and breaks RDP connections with the symtoms of hangs and black screens. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3608-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Tobias Frost October 07, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : vinagre Version : 3.22.0-6+deb10u1 CVE ID : Debian Bug : 983533 It has been found that the update of freerdp2 (see DLA-3606-1) exposed a bug in vinagre, which causes crashes and breaks RDP connections with the symtoms of hangs and black screens. Note: sha256 is now used instead of sha1 to fingerprint certificates. This will invalidate all hosts in FreeRDP known_hosts2 file, $HOME/.config/freerdp/known_hosts2. In case of problems with the connection, try removing that file. For Debian 10 buster, this problem has been fixed in version 3.22.0-6+deb10u1. We recommend that you upgrade your vinagre packages. For the detailed security status of vinagre please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/vinagre Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3609-1 tackles vinagre issue leading to RDP failures. Upgrade recommended.. vinagre update, DLA-3608-1, debian DLA, freerdp2 bug fix. . LinuxSecurity.com Team

Calendar 2 Oct 07, 2023 Debian LTS
89

Fedora 33: Vinagre Security Advisory for FreeRDP and Remmina

Security and bug fixes for FreeRDP & Remmina.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-ac23d9e47f 2021-11-26 01:27:46.738906 --------------------------------------------------------------------------------Name : vinagre Product : Fedora 33 Version : 3.22.0 Release : 21.fc33 URL : https://wiki.gnome.org/Apps/Vinagre Summary : VNC client for GNOME Description : Vinagre is a VNC client for the GNOME desktop. With Vinagre you can have several connections open simultaneously, bookmark your servers thanks to the Favorites support, store the passwords in the GNOME keyring, and browse the network to look for VNC servers. Apart from the VNC protocol, vinagre supports Spice and RDP. --------------------------------------------------------------------------------Update Information: Security and bug fixes for FreeRDP & Remmina. --------------------------------------------------------------------------------ChangeLog: * Wed Nov 10 2021 Simone Caronni - 3.22.0-21 - Rebuild for updated FreeRDP. --------------------------------------------------------------------------------References: [ 1 ] Bug #1960201 - [abrt] remmina: rcw_after_configure_scrolled(): remmina killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1960201 [ 2 ] Bug #1986752 - [abrt] remmina: g_type_check_instance_cast(): remmina killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1986752 [ 3 ] Bug #1997002 - [abrt] remmina: pa_stream_writable_size(): remmina killed by SIGABRT https://bugzilla.redhat.com/show_bug.cgi?id=1997002 [ 4 ] Bug #2015170 - [abrt] remmina: bio_write_intern(): remmina killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=2015170 [ 5 ] Bug #2015189 - remmina-1.4.21 is available https://bugzilla.redhat.com/show_bug.cgi?id=2015189 [ 6 ] Bug #2016413 - CVE-2021-41160 freerdp: improper region checks in allclients allow out of bound write to memory [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2016413 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-ac23d9e47f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Improvements to the Vinagre VNC client in Fedora 33 feature stability patches and upgrades to FreeRDP, aimed at boosting both security measures and overall user experience.. Vinagre VNC Client, Fedora Bug Fixes, Remote Desktop Solutions, FreeRDP Enhancements. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 25, 2021 Important Fedora
98

RedHat: RHSA-2020-4683 Important: OpenSSL Security Patch Released

An update for freerdp and vinagre is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: freerdp and vinagre security, bug fix, and enhancement update Advisory ID: RHSA-2020:4647-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:4647 Issue date: 2020-11-03 CVE Names: CVE-2020-11018 CVE-2020-11019 CVE-2020-11038 CVE-2020-11039 CVE-2020-11040 CVE-2020-11041 CVE-2020-11042 CVE-2020-11043 CVE-2020-11044 CVE-2020-11045 CVE-2020-11046 CVE-2020-11047 CVE-2020-11048 CVE-2020-11049 CVE-2020-11058 CVE-2020-11085 CVE-2020-11086 CVE-2020-11087 CVE-2020-11088 CVE-2020-11089 CVE-2020-11522 CVE-2020-11525 CVE-2020-11526 CVE-2020-13396 CVE-2020-13397 ==================================================================== 1. Summary: An update for freerdp and vinagre is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 8) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windowsmachines, xrdp, and VirtualBox. The vinagre packages provide the Vinagre remote desktop viewer for the GNOME desktop. The following packages have been upgraded to a later upstream version: freerdp (2.1.1). (BZ#1834287) Security Fix(es): * freerdp: Out of bound read in cliprdr_server_receive_capabilities (CVE-2020-11018) * freerdp: Out of bound read/write in usb redirection channel (CVE-2020-11039) * freerdp: out-of-bounds read in update_read_icon_info function (CVE-2020-11042) * freerdp: out-of-bounds read in autodetect_recv_bandwidth_measure_results function (CVE-2020-11047) * freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c. (CVE-2020-13396) * freerdp: Out-of-bounds read in security_fips_decrypt in libfreerdp/core/security.c (CVE-2020-13397) * freerdp: Out of bound read in update_recv could result in a crash (CVE-2020-11019) * freerdp: Integer overflow in VIDEO channel (CVE-2020-11038) * freerdp: Out of bound access in clear_decompress_subcode_rlex (CVE-2020-11040) * freerdp: Unchecked read of array offset in rdpsnd_recv_wave2_pdu (CVE-2020-11041) * freerdp: out of bound read in rfx_process_message_tileset (CVE-2020-11043) * freerdp: double free in update_read_cache_bitmap_v3_order function (CVE-2020-11044) * freerdp: out of bounds read in update_read_bitmap_data function (CVE-2020-11045) * freerdp: out of bounds seek in update_read_synchronize function could lead out of bounds read (CVE-2020-11046) * freerdp: out-of-bounds read could result in aborting the session (CVE-2020-11048) * freerdp: out-of-bound read of client memory that is then passed on to the protocol parser (CVE-2020-11049) * freerdp: stream out-of-bounds seek in rdp_read_font_capability_set could lead to out-of-bounds read (CVE-2020-11058) * freerdp: out-of-bounds read in cliprdr_read_format_list function (CVE-2020-11085) * freerdp: out-of-bounds read in ntlm_read_ntlm_v2_client_challenge function (CVE-2020-11086) * freerdp: out-of-bounds read inntlm_read_AuthenticateMessage (CVE-2020-11087) * freerdp: out-of-bounds read in ntlm_read_NegotiateMessage (CVE-2020-11088) * freerdp: out-of-bounds read in irp functions (CVE-2020-11089) * freerdp: out-of-bounds read in gdi.c (CVE-2020-11522) * freerdp: out-of-bounds read in bitmap.c (CVE-2020-11525) * freerdp: Stream pointer out of bounds in update_recv_secondary_order could lead out of bounds read later (CVE-2020-11526) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1761144 - Remove unsupported options from xfreerdp /help 1803054 - SCARD_INSUFFICIENT_BUFFER error when connecting to Windows 10 system 1834287 - Update freerdp to 2.1.1 1835382 - CVE-2020-11042 freerdp: out-of-bounds read in update_read_icon_info function 1835391 - CVE-2020-11044 freerdp: double free in update_read_cache_bitmap_v3_order function 1835399 - CVE-2020-11045 freerdp: out of bounds read in update_read_bitmap_data function 1835403 - CVE-2020-11046 freerdp: out of bounds seek in update_read_synchronize function could lead out of bounds read 1835762 - CVE-2020-11047 freerdp: out-of-bounds read in autodetect_recv_bandwidth_measure_results function 1835766 - CVE-2020-11048 freerdp: out-of-bounds read could result in aborting the session 1835772 - CVE-2020-11049 freerdp: out-of-bound read of client memory that is then passed on to the protocol parser 1835779 - CVE-2020-11058 freerdp: stream out-of-bounds seek in rdp_read_font_capability_set could lead to out-of-bounds read 1836223 - CVE-2020-11522 freerdp: out-of-bounds read ingdi.c 1836239 - CVE-2020-11525 freerdp: out-of-bounds read in bitmap.c 1836247 - CVE-2020-11526 freerdp: Stream pointer out of bounds in update_recv_secondary_order could lead out of bounds read later 1839744 - Rebuild vinagre against new freerdp 1841189 - CVE-2020-13396 freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c. 1841196 - CVE-2020-13397 freerdp: Out-of-bounds read in security_fips_decrypt in libfreerdp/core/security.c 1844161 - CVE-2020-11085 freerdp: out-of-bounds read in cliprdr_read_format_list function 1844166 - CVE-2020-11086 freerdp: out-of-bounds read in ntlm_read_ntlm_v2_client_challenge function 1844171 - CVE-2020-11087 freerdp: out-of-bounds read in ntlm_read_AuthenticateMessage 1844177 - CVE-2020-11088 freerdp: out-of-bounds read in ntlm_read_NegotiateMessage 1844184 - CVE-2020-11089 freerdp: out-of-bounds read in irp functions 1848008 - CVE-2020-11018 freerdp: Out of bound read in cliprdr_server_receive_capabilities 1848012 - CVE-2020-11019 freerdp: Out of bound read in update_recv could result in a crash 1848018 - CVE-2020-11038 freerdp: Integer overflow in VIDEO channel 1848022 - CVE-2020-11039 freerdp: Out of bound read/write in usb redirection channel 1848029 - CVE-2020-11040 freerdp: Out of bound access in clear_decompress_subcode_rlex 1848034 - CVE-2020-11041 freerdp: Unchecked read of array offset in rdpsnd_recv_wave2_pdu 1848038 - CVE-2020-11043 freerdp: out of bound read in rfx_process_message_tileset 6. Package List: Red Hat Enterprise Linux AppStream (v.8): Source: freerdp-2.1.1-1.el8.src.rpm vinagre-3.22.0-23.el8.src.rpm aarch64: freerdp-2.1.1-1.el8.aarch64.rpm freerdp-debuginfo-2.1.1-1.el8.aarch64.rpm freerdp-debugsource-2.1.1-1.el8.aarch64.rpm freerdp-libs-2.1.1-1.el8.aarch64.rpm freerdp-libs-debuginfo-2.1.1-1.el8.aarch64.rpm libwinpr-2.1.1-1.el8.aarch64.rpm libwinpr-debuginfo-2.1.1-1.el8.aarch64.rpm libwinpr-devel-2.1.1-1.el8.aarch64.rpm vinagre-3.22.0-23.el8.aarch64.rpm vinagre-debuginfo-3.22.0-23.el8.aarch64.rpm vinagre-debugsource-3.22.0-23.el8.aarch64.rpm ppc64le: freerdp-2.1.1-1.el8.ppc64le.rpm freerdp-debuginfo-2.1.1-1.el8.ppc64le.rpm freerdp-debugsource-2.1.1-1.el8.ppc64le.rpm freerdp-libs-2.1.1-1.el8.ppc64le.rpm freerdp-libs-debuginfo-2.1.1-1.el8.ppc64le.rpm libwinpr-2.1.1-1.el8.ppc64le.rpm libwinpr-debuginfo-2.1.1-1.el8.ppc64le.rpm libwinpr-devel-2.1.1-1.el8.ppc64le.rpm vinagre-3.22.0-23.el8.ppc64le.rpm vinagre-debuginfo-3.22.0-23.el8.ppc64le.rpm vinagre-debugsource-3.22.0-23.el8.ppc64le.rpm s390x: freerdp-2.1.1-1.el8.s390x.rpm freerdp-debuginfo-2.1.1-1.el8.s390x.rpm freerdp-debugsource-2.1.1-1.el8.s390x.rpm freerdp-libs-2.1.1-1.el8.s390x.rpm freerdp-libs-debuginfo-2.1.1-1.el8.s390x.rpm libwinpr-2.1.1-1.el8.s390x.rpm libwinpr-debuginfo-2.1.1-1.el8.s390x.rpm libwinpr-devel-2.1.1-1.el8.s390x.rpm vinagre-3.22.0-23.el8.s390x.rpm vinagre-debuginfo-3.22.0-23.el8.s390x.rpm vinagre-debugsource-3.22.0-23.el8.s390x.rpm x86_64: freerdp-2.1.1-1.el8.x86_64.rpm freerdp-debuginfo-2.1.1-1.el8.i686.rpm freerdp-debuginfo-2.1.1-1.el8.x86_64.rpm freerdp-debugsource-2.1.1-1.el8.i686.rpm freerdp-debugsource-2.1.1-1.el8.x86_64.rpm freerdp-libs-2.1.1-1.el8.i686.rpm freerdp-libs-2.1.1-1.el8.x86_64.rpm freerdp-libs-debuginfo-2.1.1-1.el8.i686.rpm freerdp-libs-debuginfo-2.1.1-1.el8.x86_64.rpm libwinpr-2.1.1-1.el8.i686.rpm libwinpr-2.1.1-1.el8.x86_64.rpm libwinpr-debuginfo-2.1.1-1.el8.i686.rpm libwinpr-debuginfo-2.1.1-1.el8.x86_64.rpm libwinpr-devel-2.1.1-1.el8.i686.rpm libwinpr-devel-2.1.1-1.el8.x86_64.rpm vinagre-3.22.0-23.el8.x86_64.rpm vinagre-debuginfo-3.22.0-23.el8.x86_64.rpm vinagre-debugsource-3.22.0-23.el8.x86_64.rpm Red Hat CodeReady Linux Builder (v. 8): aarch64: freerdp-debuginfo-2.1.1-1.el8.aarch64.rpm freerdp-debugsource-2.1.1-1.el8.aarch64.rpm freerdp-devel-2.1.1-1.el8.aarch64.rpm freerdp-libs-debuginfo-2.1.1-1.el8.aarch64.rpm libwinpr-debuginfo-2.1.1-1.el8.aarch64.rpm ppc64le: freerdp-debuginfo-2.1.1-1.el8.ppc64le.rpm freerdp-debugsource-2.1.1-1.el8.ppc64le.rpm freerdp-devel-2.1.1-1.el8.ppc64le.rpm freerdp-libs-debuginfo-2.1.1-1.el8.ppc64le.rpm libwinpr-debuginfo-2.1.1-1.el8.ppc64le.rpm s390x: freerdp-debuginfo-2.1.1-1.el8.s390x.rpm freerdp-debugsource-2.1.1-1.el8.s390x.rpm freerdp-devel-2.1.1-1.el8.s390x.rpm freerdp-libs-debuginfo-2.1.1-1.el8.s390x.rpm libwinpr-debuginfo-2.1.1-1.el8.s390x.rpm x86_64: freerdp-debuginfo-2.1.1-1.el8.i686.rpm freerdp-debuginfo-2.1.1-1.el8.x86_64.rpm freerdp-debugsource-2.1.1-1.el8.i686.rpm freerdp-debugsource-2.1.1-1.el8.x86_64.rpm freerdp-devel-2.1.1-1.el8.i686.rpm freerdp-devel-2.1.1-1.el8.x86_64.rpm freerdp-libs-debuginfo-2.1.1-1.el8.i686.rpm freerdp-libs-debuginfo-2.1.1-1.el8.x86_64.rpm libwinpr-debuginfo-2.1.1-1.el8.i686.rpm libwinpr-debuginfo-2.1.1-1.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2020-11018 https://access.redhat.com/security/cve/CVE-2020-11019 https://access.redhat.com/security/cve/CVE-2020-11038 https://access.redhat.com/security/cve/CVE-2020-11039 https://access.redhat.com/security/cve/CVE-2020-11040 https://access.redhat.com/security/cve/CVE-2020-11041 https://access.redhat.com/security/cve/CVE-2020-11042 https://access.redhat.com/security/cve/CVE-2020-11043 https://access.redhat.com/security/cve/CVE-2020-11044 https://access.redhat.com/security/cve/CVE-2020-11045 https://access.redhat.com/security/cve/CVE-2020-11046 https://access.redhat.com/security/cve/CVE-2020-11047 https://access.redhat.com/security/cve/CVE-2020-11048 https://access.redhat.com/security/cve/CVE-2020-11049 https://access.redhat.com/security/cve/CVE-2020-11058 https://access.redhat.com/security/cve/CVE-2020-11085 https://access.redhat.com/security/cve/CVE-2020-11086 https://access.redhat.com/security/cve/CVE-2020-11087 https://access.redhat.com/security/cve/CVE-2020-11088 https://access.redhat.com/security/cve/CVE-2020-11089 https://access.redhat.com/security/cve/CVE-2020-11522 https://access.redhat.com/security/cve/CVE-2020-11525 https://access.redhat.com/security/cve/CVE-2020-11526 https://access.redhat.com/security/cve/CVE-2020-13396 https://access.redhat.com/security/cve/CVE-2020-13397 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBX6I0INzjgjWX9erEAQh3aA//RtOjgT5U/N0RZODK/NW0Ie1HZFE1NIlA P6lqlGko8xf7ojkAfzKYqsfipMmencaYrVc0dqCUd5WoJttkVQzWpsTZb8qDaCW8 Q7ps0gwyLYZnTCFc1j0NYV35E8tSoyRj+IkDTdpTiSQlr6+bczxhIILqi1hoM3fa IJ91rqM4JzhXlFzOZMMi+xCHVxoszrbFf2ivJkCr9esJF+4N0R1ec31JhtxPEcc7 rG5eB1c3sIoKeIn4PYJ9duj6i+0AOcBuhbFArXqE1aPy/InfVaQltgwzR1ZF9HVS SFompoeTPs6iEp0KpcoM7xNtGeUO50OhR3j2NRseiS72+TB+N3091wwHBWZ1n7Jb SWCV1ZduvfQcnIWRMUjtgk5lPzuRTvotip/BwOaaKMOs7Xzh7Y6wvlIbFMDWt2YY V5qbxKG32Zt53Sq9m8KJ15aRKJt5K1UdPDV6KnKzjHATcIazWyCWhy5c/T5zWcMq qk+dmZv8/EA4pKaXYxkG836ZTccOftXAM3U6zUfB60Bm5ehXR45HRRuZub4C97to +eP+HvgIR5+mCO62hEZfjnC8c4mJIryJaAWnb8hpaQgWXZnTdEl4oQAh/zIJl61X BkYiCJ0fgTO6D7CGe72mORCx1FQ7Sjq1chhqpl8CZQKLaqJx1xbJ2ZZwuhg5OriJ FwblVM9hMdA=mptC -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Recent security patches for Freerdp and Vinagre on Red Hat Enterprise Linux 8 address multiple vulnerabilities, offering detailed insights on the fixes and impacts. Freerdp Updates, Red Hat Enterprise, Remote Desktop Protocol, Bug Fixes, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 03, 2020 Important Red Hat
200

SciLinux: SLSA-2019-2157-1 Low: freerdp Out Of Bounds Threat

freerdp: out of bounds read in drdynvc_process_capability_request (CVE-2018-1000852) SL7 x86_64 vinagre-3.22.0-12.el7.i686.rpm freerdp-libs-2.0.0-1.rc4.el7.x86_64.rpm libwinpr-2.0.0-1.rc4.el7.x86_64.rpm vinagre-3.22.0-12.el7.x86_64.rpm freerdp-2.0.0-1.rc4.el7.x86_64.rpm libwinpr-2.0.0-1.rc4.el7.i686.rpm freerdp-libs-2.0.0-1.rc4.el7.i686.rpm libwinpr-devel-2.0 [More...]. Synopsis: Low: freerdp and vinagre security, bug fix, and enhancement update Advisory ID: SLSA-2019:2157-1 Issue Date: 2019-08-06 CVE Numbers: CVE-2018-1000852 -- The vinagre packages provide the Vinagre remote desktop viewer for the GNOME desktop. The following packages have been upgraded to a later upstream version: freerdp (2.0.0). Security Fix(es): * freerdp: out of bounds read in drdynvc_process_capability_request (CVE-2018-1000852) -- SL7 x86_64 vinagre-3.22.0-12.el7.i686.rpm freerdp-libs-2.0.0-1.rc4.el7.x86_64.rpm libwinpr-2.0.0-1.rc4.el7.x86_64.rpm vinagre-3.22.0-12.el7.x86_64.rpm freerdp-2.0.0-1.rc4.el7.x86_64.rpm libwinpr-2.0.0-1.rc4.el7.i686.rpm freerdp-libs-2.0.0-1.rc4.el7.i686.rpm libwinpr-devel-2.0.0-1.rc4.el7.x86_64.rpm libwinpr-devel-2.0.0-1.rc4.el7.i686.rpm freerdp-devel-2.0.0-1.rc4.el7.x86_64.rpm freerdp-devel-2.0.0-1.rc4.el7.i686.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.i686.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.x86_64.rpm vinagre-debuginfo-3.22.0-12.el7.i686.rpm vinagre-debuginfo-3.22.0-12.el7.x86_64.rpm - Scientific Linux Development Team . Minor update for remmina and rdesktop fixing buffer overflow vulnerabilities, alongside various patches and improvements.. freerdp update,vulnerability fix,vinagre security,remote desktop viewer. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Aug 26, 2019 Low Scientific Linux
98

Red Hat Enterprise Linux 7: RHSA-2019-2157 Low: freerdp and vinagre Bug Fix

An update for freerdp and vinagre is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: freerdp and vinagre security, bug fix, and enhancement update Advisory ID: RHSA-2019:2157-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:2157 Issue date: 2019-08-06 CVE Names: CVE-2018-1000852 ==================================================================== 1. Summary: An update for freerdp and vinagre is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox. The vinagre packages provide the Vinagre remote desktop viewer for the GNOME desktop. The following packages have been upgraded to a later upstream version: freerdp (2.0.0). (BZ#1291254) Security Fix(es): * freerdp: out of bounds read indrdynvc_process_capability_request (CVE-2018-1000852) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1291254 - Rebase FreeRDP to newer version 1569552 - vinagre does not accept passwords longer than 20 characters1661640 - CVE-2018-1000852 freerdp: out of bounds read in drdynvc_process_capability_request 1680229 - Rebuild vinagre against new freerdp 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: freerdp-2.0.0-1.rc4.el7.src.rpm vinagre-3.22.0-12.el7.src.rpm x86_64: freerdp-2.0.0-1.rc4.el7.x86_64.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.i686.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.x86_64.rpm freerdp-libs-2.0.0-1.rc4.el7.i686.rpm freerdp-libs-2.0.0-1.rc4.el7.x86_64.rpm libwinpr-2.0.0-1.rc4.el7.i686.rpm libwinpr-2.0.0-1.rc4.el7.x86_64.rpm vinagre-3.22.0-12.el7.i686.rpm vinagre-3.22.0-12.el7.x86_64.rpm vinagre-debuginfo-3.22.0-12.el7.i686.rpm vinagre-debuginfo-3.22.0-12.el7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: freerdp-debuginfo-2.0.0-1.rc4.el7.i686.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.x86_64.rpm freerdp-devel-2.0.0-1.rc4.el7.i686.rpm freerdp-devel-2.0.0-1.rc4.el7.x86_64.rpm libwinpr-devel-2.0.0-1.rc4.el7.i686.rpm libwinpr-devel-2.0.0-1.rc4.el7.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: freerdp-2.0.0-1.rc4.el7.src.rpm vinagre-3.22.0-12.el7.src.rpm ppc64: freerdp-2.0.0-1.rc4.el7.ppc64.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.ppc.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.ppc64.rpm freerdp-libs-2.0.0-1.rc4.el7.ppc.rpm freerdp-libs-2.0.0-1.rc4.el7.ppc64.rpm libwinpr-2.0.0-1.rc4.el7.ppc.rpm libwinpr-2.0.0-1.rc4.el7.ppc64.rpm vinagre-3.22.0-12.el7.ppc.rpm vinagre-3.22.0-12.el7.ppc64.rpm vinagre-debuginfo-3.22.0-12.el7.ppc.rpm vinagre-debuginfo-3.22.0-12.el7.ppc64.rpm ppc64le: freerdp-2.0.0-1.rc4.el7.ppc64le.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.ppc64le.rpm freerdp-libs-2.0.0-1.rc4.el7.ppc64le.rpm libwinpr-2.0.0-1.rc4.el7.ppc64le.rpm vinagre-3.22.0-12.el7.ppc64le.rpm vinagre-debuginfo-3.22.0-12.el7.ppc64le.rpm s390x: freerdp-2.0.0-1.rc4.el7.s390x.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.s390.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.s390x.rpm freerdp-libs-2.0.0-1.rc4.el7.s390.rpm freerdp-libs-2.0.0-1.rc4.el7.s390x.rpm libwinpr-2.0.0-1.rc4.el7.s390.rpm libwinpr-2.0.0-1.rc4.el7.s390x.rpm vinagre-3.22.0-12.el7.s390.rpm vinagre-3.22.0-12.el7.s390x.rpm vinagre-debuginfo-3.22.0-12.el7.s390.rpm vinagre-debuginfo-3.22.0-12.el7.s390x.rpm x86_64: freerdp-2.0.0-1.rc4.el7.x86_64.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.i686.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.x86_64.rpm freerdp-libs-2.0.0-1.rc4.el7.i686.rpm freerdp-libs-2.0.0-1.rc4.el7.x86_64.rpm libwinpr-2.0.0-1.rc4.el7.i686.rpm libwinpr-2.0.0-1.rc4.el7.x86_64.rpm vinagre-3.22.0-12.el7.i686.rpm vinagre-3.22.0-12.el7.x86_64.rpm vinagre-debuginfo-3.22.0-12.el7.i686.rpm vinagre-debuginfo-3.22.0-12.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): ppc64: freerdp-debuginfo-2.0.0-1.rc4.el7.ppc.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.ppc64.rpm freerdp-devel-2.0.0-1.rc4.el7.ppc.rpm freerdp-devel-2.0.0-1.rc4.el7.ppc64.rpm libwinpr-devel-2.0.0-1.rc4.el7.ppc.rpm libwinpr-devel-2.0.0-1.rc4.el7.ppc64.rpm ppc64le: freerdp-debuginfo-2.0.0-1.rc4.el7.ppc64le.rpm freerdp-devel-2.0.0-1.rc4.el7.ppc64le.rpm libwinpr-devel-2.0.0-1.rc4.el7.ppc64le.rpm s390x: freerdp-debuginfo-2.0.0-1.rc4.el7.s390.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.s390x.rpm freerdp-devel-2.0.0-1.rc4.el7.s390.rpm freerdp-devel-2.0.0-1.rc4.el7.s390x.rpm libwinpr-devel-2.0.0-1.rc4.el7.s390.rpm libwinpr-devel-2.0.0-1.rc4.el7.s390x.rpm x86_64: freerdp-debuginfo-2.0.0-1.rc4.el7.i686.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.x86_64.rpm freerdp-devel-2.0.0-1.rc4.el7.i686.rpm freerdp-devel-2.0.0-1.rc4.el7.x86_64.rpm libwinpr-devel-2.0.0-1.rc4.el7.i686.rpm libwinpr-devel-2.0.0-1.rc4.el7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: freerdp-2.0.0-1.rc4.el7.src.rpm vinagre-3.22.0-12.el7.src.rpm x86_64: freerdp-2.0.0-1.rc4.el7.x86_64.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.i686.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.x86_64.rpm freerdp-libs-2.0.0-1.rc4.el7.i686.rpm freerdp-libs-2.0.0-1.rc4.el7.x86_64.rpm libwinpr-2.0.0-1.rc4.el7.i686.rpm libwinpr-2.0.0-1.rc4.el7.x86_64.rpm vinagre-3.22.0-12.el7.i686.rpm vinagre-3.22.0-12.el7.x86_64.rpm vinagre-debuginfo-3.22.0-12.el7.i686.rpm vinagre-debuginfo-3.22.0-12.el7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: freerdp-debuginfo-2.0.0-1.rc4.el7.i686.rpm freerdp-debuginfo-2.0.0-1.rc4.el7.x86_64.rpm freerdp-devel-2.0.0-1.rc4.el7.i686.rpm freerdp-devel-2.0.0-1.rc4.el7.x86_64.rpm libwinpr-devel-2.0.0-1.rc4.el7.i686.rpm libwinpr-devel-2.0.0-1.rc4.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2018-1000852 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.7_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXUl2p9zjgjWX9erEAQiY0g/+JGkx1ae0MUd5fG766rNKBoDguodFhxhY HTC1JGc1/LwnOWjKQXIWylQh/ceYnh3577F2m8q4J8X00Y8k14AElfGSRza3wjaK C/fWX6DcPUZoNE1/1nXkP03i1ZOWERudlCJSap0Pak4RVaHVinCDDfFTAntAoGhb craHUB0jxN7i4NFWZcGUNgTfj8Gj/n0IdxlY8f/IVGw8ZUoenNihuRwVJ5c+guni Kn4BW74IJmUIVdwcvhRLfOCsG+JRyNYTtPYbdQVLxkUfMu8tXBpO7eGW7+U3MO/T +UWfqfH3eBlwILJUavayNNEs8XNZ+onq+QNyMC0KLWcdfdwksQww/QssT/ydGACG uIDnEXD7/Q0n5673oLwPo9enbk6nI9Y/paHdEQaceKGDcN+UOmiEM/bDQizsz4Wr wwEeIsySije5rKL66dlTb45lfRb4czGUPObgpZRrb5kD7vmosvDuCC4MYWyXDnTa IhX++9I8eob34m2bnB19VJw4xVxV274cSpYIP/EgwjdGTMxmnkxnKlsi9f7fiCDM 04URWoHDg6gHK6frKd9Q1ebk7dmvNgVFZ2vd5H+xiDyHJPiGUkoCeT7qzsOtBats /Swuwp9IN9gpIYCcVQcQl1LGkVJR+KWpu3bpRybqU1aj/p9DRZxJWQ4F2k1Ey6FM ux5dX95Owfs=+SjQ -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A new release for freerdp and vinagre in Red Hat Enterprise Linux 7 tackles a minor security vulnerability along with several bug corrections.. freerdp security update, vinagre bug fix, Red Hat advisory, enterprise Linux enhancements. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Aug 06, 2019 Low Red Hat
91

Gentoo: 200903-01 Normal: Vinagre User-Assisted Code Execution

A format string error in Vinagre may allow for the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Vinagre: User-assisted execution of arbitrary code Date: March 06, 2009 Bugs: #250314 ID: 200903-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A format string error in Vinagre may allow for the execution of arbitrary code. Background ========= Vinagre is a VNC Client for the GNOME Desktop. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/vinagre < 0.5.2 > = 0.5.2 Description ========== Alfredo Ortega (Core Security Technologies) reported a format string error in the vinagre_utils_show_error() function in src/vinagre-utils.c. Impact ===== A remote attacker could entice a user into opening a specially crafted .vnc file or connecting to a malicious server, possibly resulting in the remote execution of arbitrary code with the privileges of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All Vinagre users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-misc/vinagre-0.5.2" References ========= [ 1 ] CVE-2008-5660 https://www.cve.org/CVERecord?id=CVE-2008-5660 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200903-01 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2009 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo Linux Advisory GLSA 202302-05 outlines a vulnerability in the GIMP software. Users are encouraged to apply the latest updates for secure operation.. Vinagre Security Advisory, Gentoo Update, Arbitrary Code Execution. . LinuxSecurity.com Team

Calendar 2 Mar 06, 2009 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here