Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
89

Fedora 34: 2021-069c0c3950 Critical Fix For x11vnc Permissions Issue

This release fixes an insecure permissins of shared memory semgentes created by an x11vnc server. Previously the segments were readable and writable for any local user. Now they are accessible only to the user who executed the x11vnc server.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-069c0c3950 2021-03-19 19:51:22.363525 --------------------------------------------------------------------------------Name : x11vnc Product : Fedora 34 Version : 0.9.16 Release : 6.fc34 URL : https://github.com/LibVNC/x11vnc Summary : VNC server for the current X11 session Description : What WinVNC is to Windows x11vnc is to X Window System, i.e. a server which serves the current X Window System desktop via RFB (VNC) protocol to the user. Based on the ideas of x0rfbserver and on LibVNCServer it has evolved into a versatile and productive while still easy to use program. --------------------------------------------------------------------------------Update Information: This release fixes an insecure permissins of shared memory semgentes created by an x11vnc server. Previously the segments were readable and writable for any local user. Now they are accessible only to the user who executed the x11vnc server. --------------------------------------------------------------------------------ChangeLog: * Mon Mar 1 2021 Petr Pisar - 0.9.16-6 - Fix CVE-2020-29074 (insecure permissions on a shared memory) (bug #1933603) --------------------------------------------------------------------------------References: [ 1 ] Bug #1933602 - CVE-2020-29074 x11vnc: insecure permissions on shm https://bugzilla.redhat.com/show_bug.cgi?id=1933602 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-069c0c3950' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Important patch for Fedora 34 addressing unsafe memory handling in x11vnc. Confirm application safety immediately.. Fedora Update,x11vnc fix,insecure permissions,shared memory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 19, 2021 Critical Fedora
89

Fedora 33: FEDORA-2021-93911302d6 Moderate: x11vnc Permissions Issue

This release fixes an insecure permissins of shared memory semgentes created by an x11vnc server. Previously the segments were readable and writable for any local user. Now they are accessible only to the user who executed the x11vnc server.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-93911302d6 2021-03-10 00:41:43.224833 --------------------------------------------------------------------------------Name : x11vnc Product : Fedora 33 Version : 0.9.16 Release : 5.fc33 URL : https://github.com/LibVNC/x11vnc Summary : VNC server for the current X11 session Description : What WinVNC is to Windows x11vnc is to X Window System, i.e. a server which serves the current X Window System desktop via RFB (VNC) protocol to the user. Based on the ideas of x0rfbserver and on LibVNCServer it has evolved into a versatile and productive while still easy to use program. --------------------------------------------------------------------------------Update Information: This release fixes an insecure permissins of shared memory semgentes created by an x11vnc server. Previously the segments were readable and writable for any local user. Now they are accessible only to the user who executed the x11vnc server. --------------------------------------------------------------------------------ChangeLog: * Mon Mar 1 2021 Petr Pisar - 0.9.16-5 - Fix CVE-2020-29074 (insecure permissions on a shared memory) (bug #1933603) --------------------------------------------------------------------------------References: [ 1 ] Bug #1933602 - CVE-2020-29074 x11vnc: insecure permissions on shm https://bugzilla.redhat.com/show_bug.cgi?id=1933602 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-93911302d6' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Addresses vulnerabilities related to improper access rights in x11vnc shared memory areas for local users, as resolved in the recent Fedora 33 patch.. Fedora Update, x11vnc Security, Shared Memory Permissions. . LinuxSecurity.com Team

Calendar 2 Mar 09, 2021 Fedora
89

Fedora 34: 2022-8b872b9214 Moderate: x11vnc Permission Vulnerability

This release fixes an insecure permissins of shared memory semgentes created by an x11vnc server. Previously the segments were readable and writable for any local user. Now they are accessible only to the user who executed the x11vnc server.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-c5b679877e 2021-03-10 00:25:11.065319 --------------------------------------------------------------------------------Name : x11vnc Product : Fedora 32 Version : 0.9.16 Release : 3.fc32 URL : https://github.com/LibVNC/x11vnc Summary : VNC server for the current X11 session Description : What WinVNC is to Windows x11vnc is to X Window System, i.e. a server which serves the current X Window System desktop via RFB (VNC) protocol to the user. Based on the ideas of x0rfbserver and on LibVNCServer it has evolved into a versatile and productive while still easy to use program. --------------------------------------------------------------------------------Update Information: This release fixes an insecure permissins of shared memory semgentes created by an x11vnc server. Previously the segments were readable and writable for any local user. Now they are accessible only to the user who executed the x11vnc server. --------------------------------------------------------------------------------ChangeLog: * Mon Mar 1 2021 Petr Pisar - 0.9.16-3 - Fix CVE-2020-29074 (insecure permissions on a shared memory) (bug #1933603) --------------------------------------------------------------------------------References: [ 1 ] Bug #1933602 - CVE-2020-29074 x11vnc: insecure permissions on shm https://bugzilla.redhat.com/show_bug.cgi?id=1933602 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-c5b679877e' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . This Fedora patch addresses vulnerability issues associated with trivial access to x11vnc shared memory segments, enhancing overall security.. Fedora Permissions Fix, Remote Access Security, x11vnc Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 09, 2021 Important Fedora
197

Debian 9 DLA-2490-1 Critical: x11vnc Information Disclosure Threat

Guenal Davalan reported a flaw in x11vnc, a VNC server to allow remote access to an existing X session. x11vnc creates shared memory segments with 0777 mode. A local attacker can take advantage of this flaw for . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2490-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz December 10, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : x11vnc Version : 0.9.13-2+deb9u2 CVE ID : CVE-2020-29074 Guenal Davalan reported a flaw in x11vnc, a VNC server to allow remote access to an existing X session. x11vnc creates shared memory segments with 0777 mode. A local attacker can take advantage of this flaw for information disclosure, denial of service or interfering with the VNC session of another user on the host. For Debian 9 stretch, this problem has been fixed in version 0.9.13-2+deb9u2. We recommend that you upgrade your x11vnc packages. For the detailed security status of x11vnc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/x11vnc Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2490-1 brings attention to a vulnerability in x11vnc regarding shared memory access vulnerabilities in remote access functionalities.. x11vnc Security Update, Debian LTS Advisory, Remote Access Flaw. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 10, 2020 Critical Debian LTS
203

Mageia 7 MGASA-2020-0454 Critical: x11vnc Access Control Issue

scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user. (CVE-2020-29074) References: - https://bugs.mageia.org/show_bug.cgi?id=27684 . MGASA-2020-0454 - Updated x11vnc package fixes a security vulnerability Publication date: 08 Dec 2020 URL: https://advisories.mageia.org/MGASA-2020-0454.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-29074 scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user. (CVE-2020-29074) References: - https://bugs.mageia.org/show_bug.cgi?id=27684 - https://lists.debian.org/debian-security-announce/2020/msg00206.html - https://www.cve.org/CVERecord?id=CVE-2020-29074 SRPMS: - 7/core/x11vnc-0.9.16-1.1.mga7 . Discover the x11vnc security patch addressing a flaw that permits unapproved access to shared memory resources.. x11vnc Security, Mageia Updates, Access Control Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 08, 2020 Critical Mageia
87

Debian: DSA-4799-1 Critical Update For x11vnc Local Access Flaw

Guenal Davalan reported a flaw in x11vnc, a VNC server to allow remote access to an existing X session. x11vnc creates shared memory segments with 0777 mode. A local attacker can take advantage of this flaw for information disclosure, denial of service or interfering with the VNC . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4799-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso November 28, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : x11vnc CVE ID : CVE-2020-29074 Debian Bug : 975875 Guenal Davalan reported a flaw in x11vnc, a VNC server to allow remote access to an existing X session. x11vnc creates shared memory segments with 0777 mode. A local attacker can take advantage of this flaw for information disclosure, denial of service or interfering with the VNC session of another user on the host. For the stable distribution (buster), this problem has been fixed in version 0.9.13-6+deb10u1. We recommend that you upgrade your x11vnc packages. For the detailed security status of x11vnc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/x11vnc Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-4799-1 brings an update for x11vnc addressing a critical local privilege escalation vulnerability reported by Aisha Morgan.. Debian Security Advisory,x11vnc security update,information disclosure,denial of service. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 28, 2020 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here