Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Update to 2.14 This updates ensures that the VNC server used for debugging is bound to the local interfaces. Previously the VNC server might have been available globally depending on the system's firewall settings.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-c5c870e3ab 2018-07-03 16:49:24.958505 --------------------------------------------------------------------------------Name : standard-test-roles Product : Fedora 28 Version : 2.14 Release : 1.fc28 URL : https://fedoraproject.org/wiki/Changes/InvokingTestsAnsible Summary : Standard Test Interface Ansible roles Description : Shared Ansible roles to support the Standard Test Interface as described at https://fedoraproject.org/wiki/Changes/InvokingTestsAnsible. --------------------------------------------------------------------------------Update Information: Update to 2.14 This updates ensures that the VNC server used for debugging is bound to the local interfaces. Previously the VNC server might have been available globally depending on the system's firewall settings. --------------------------------------------------------------------------------ChangeLog: * Fri Jun 29 2018 Andrei Stepanov - 2.14-1 - Build with the latest merged PRs. * Fri May 25 2018 Andrei Stepanov - 2.13-2 - Build with the latest merged PRs. * Wed May 23 2018 Andrei Stepanov - 2.12-1 - Build with the latest merged PRs. * Mon May 21 2018 Andrei Stepanov - 2.11-1 - Build with the latest merged PRs. * Mon Apr 23 2018 Andrei Stepanov - 2.10-1 - Build with the latest merged PRs. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-c5c870e3ab' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signedwith the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
A buffer overflow in TigerVNC could result in execution of arbitrary code or Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201411-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: TigerVNC: User-assisted execution of arbitrary code Date: November 05, 2014 Bugs: #505170 ID: 201411-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A buffer overflow in TigerVNC could result in execution of arbitrary code or Denial of Service. Background ========= TigerVNC is a high-performance VNC server/client. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/tigervnc < 1.3.1 > = 1.3.1 Description ========== Two boundary errors in TigerVNC could lead to a heap-based buffer overflow. Impact ===== A remote attacker could entice a user to connect to a malicious VNC server using TigerVNC, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All TigerVNC users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-misc/tigervnc-1.3.1" References ========= [ 1 ] CVE-2014-0011 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0011 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201411-03 Concerns? ======== Security is a primaryfocus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.