Advisories ยป MGASA-2014-0466

Updated kdenetwork4 packages fix security vulnerabilities in krfb

Publication date: 21 Nov 2014
Type: security
Affected Mageia releases : 3
CVE: CVE-2014-6053 , CVE-2014-6054 , CVE-2014-6055


A malicious VNC client can trigger multiple DoS conditions on the VNC server
by advertising a large screen size, ClientCutText message length and/or a zero
scaling factor parameter (CVE-2014-6053, CVE-2014-6054).

A malicious VNC client can trigger multiple stack-based buffer overflows by
passing a long file and directory names and/or attributes (FileTime) when
using the file transfer message feature (CVE-2014-6055).

The krfb package is built with a bundled copy of libvncserver.