Errata ID | 415 |
---|---|
Date | 2019-02-06 |
Source package | libvncserver |
Fixed in version | 0.9.11+dfsg-1.3~deb9u1 |
Description | This update addresses the following issues: * Use-after-free in file transfer extension server code allows for potential code execution (CVE-2018-6307) * Use-after-free in file transfer extension allows for potential code execution (CVE-2018-15126) * Heap out-of-bounds write in rfbserver.c:rfbProcessFileTransferReadBuffer() allows for potential code execution (CVE-2018-15127) * Multiple heap out-of-bound writes in VNC client code (CVE-2018-20019) * Heap out-of-bound write inside structure in VNC client code allows for potential code execution (CVE-2018-20020) * Infinite loop in VNC client code allows for denial of service (CVE-2018-20021) * Improper initialization in VNC client code allows for information disclosure (CVE-2018-20022) * Improper initialization in VNC Repeater client code allows for information disclosure (CVE-2018-20023) * NULL pointer dereference in VNC client code allows for denial of service (CVE-2018-20024) |
Additional notes | |
CVE ID | CVE-2018-6307 CVE-2018-15126 CVE-2018-15127 CVE-2018-20019 CVE-2018-20020 CVE-2018-20021 CVE-2018-20022 CVE-2018-20023 CVE-2018-20024 |
UCS Bug number | #48591 |