Updated gtk-vnc packages fix security vulnerability
Publication date: 20 Feb 2017Modification date: 20 Feb 2017
Type: security
Affected Mageia releases : 5
CVE: CVE-2017-5884 , CVE-2017-5885
Description
It was found that gtk-vnc code does not properly check boundaries of subrectangle-containing tiles. A malicious server can use this to overwrite parts of the client memory (CVE-2017-5884). In addition, the vnc_connection_server_message() and vnc_color_map_set() functions do not check for integer overflow properly, leading to a malicious server being able to overwrite parts of the client memory (CVE-2017-5885).
References
- https://bugs.mageia.org/show_bug.cgi?id=20244
- http://openwall.com/lists/oss-security/2017/02/05/5
- https://bugzilla.gnome.org/show_bug.cgi?id=778048
- https://bugzilla.gnome.org/show_bug.cgi?id=778050
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5884
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5885
SRPMS
5/core
- gtk-vnc-0.5.3-6.1.mga5