Debian Security Advisory
DLA-777-1 libvncserver -- LTS security update
- Date Reported:
- 03 Jan 2017
- Affected Packages:
- libvncserver
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2016-9941, CVE-2016-9942.
- More information:
-
It was discovered that there were two vulnerabilities in libvncserver, a library to create/embed a VNC server:
- CVE-2016-9941
Fix a heap-based buffer overflow that allows remote servers to cause a denial of service via a crafted FramebufferUpdate message containing a subrectangle outside of the drawing area.
- CVE-2016-9942
Fix a heap-based buffer overflow that allow remote servers to cause a denial of service via a crafted FramebufferUpdate message with the
Ultra
type tile such that the LZO decompressed payload exceeds the size of the tile dimensions.
For Debian 7
Wheezy
, these issues have been fixed in libvncserver version 0.9.9+dfsg-1+deb7u2.We recommend that you upgrade your libvncserver packages.
- CVE-2016-9941