• [SECURITY] [DSA 4221-1] libvncserver security update

    From Moritz Muehlenhoff@1:229/2 to All on Fri Jun 8 22:30:02 2018
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4221-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff
    June 08, 2018 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : libvncserver
    CVE ID : CVE-2018-7225

    Alexander Peslyak discovered that insufficient input sanitising of RFB
    packets in LibVNCServer could result in the disclosure of memory
    contents.

    For the oldstable distribution (jessie), this problem has been fixed
    in version 0.9.9+dfsg2-6.1+deb8u3.

    For the stable distribution (stretch), this problem has been fixed in
    version 0.9.11+dfsg-1+deb9u1.

    We recommend that you upgrade your libvncserver packages.

    For the detailed security status of libvncserver please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/libvncserver

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlsa5awACgkQEMKTtsN8 Tjb9wxAAvqz4FyDwnXR1bJbtN8DxhbZx2McQMj9/+wDDW9dzOe/lH4VFWr97rIpb Gx1SSp2DtpXqt0SrgIRkBJHpue5QATh/eLpM+zDmjq2sTanZ3xmKlscXBRRRjSoa lbOmmKrem35otE1PzR5T+ngZqxEvD0pwsNILHLzgEfODqllMpD4rx+JJLNHXqLQ/ VtbWILAltB+D3AFTXUBxCxQ/0khhhXAmn1HeQq3Aa0OxRFjq/UGxMTVkVtygsHXR 0zENx+AFA+np+no0wD0TdnEtgZDw8VswY8IKRvkC96wE8l7P2oCmd3QXsYys4h0F 6mmkbORVV8FeySytQwT9zQKFKCWY1fVWGSRCe7OyQOfBf4AnNDgxYfpsUQ0JNTEp Xa78JigIsSiLWx77eoei4/XabjHMnNBd9X1NnOl0SlGIUbGraPy6hLXCjsP4AaXY sDX8y7qPLU/fvLDB2ntu1+ycVtCpY8muCcUf/b5CBl3mN16k/13RLT8yPJ5CRuDz h6DIMDypR664tMGbnoJypAFqHxYMBc7dLSngGV608xodg4B4gluRlKHsN0uC9VHM MAndJdLj2DZwemQTY7pXHr599wvpAcWK81DF/6dK16yhtww848zVvGH4ul/VV1f+ PdaUDKmxkZYCZF++70a9K/8BRxqIK0BLNu2zfrz2D4j2OV2UN7U=
    =6xPo
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)