Updated kdenetwork4 packages fix security vulnerabilities in krfb
Publication date: 21 Nov 2014Modification date: 21 Nov 2014
Type: security
Affected Mageia releases : 3
CVE: CVE-2014-6053 , CVE-2014-6054 , CVE-2014-6055
Description
A malicious VNC client can trigger multiple DoS conditions on the VNC server by advertising a large screen size, ClientCutText message length and/or a zero scaling factor parameter (CVE-2014-6053, CVE-2014-6054). A malicious VNC client can trigger multiple stack-based buffer overflows by passing a long file and directory names and/or attributes (FileTime) when using the file transfer message feature (CVE-2014-6055). The krfb package is built with a bundled copy of libvncserver.
References
- https://bugs.mageia.org/show_bug.cgi?id=14205
- http://www.ocert.org/advisories/ocert-2014-007.html
- https://www.kde.org/info/security/advisory-20140923-1.txt
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6053
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6054
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6055
SRPMS
3/core
- kdenetwork4-4.10.5-1.3.mga3