Debian Security Advisory
DLA-777-1 libvncserver -- LTS security update
- Date Reported:
- 03 Jan 2017
- Affected Packages:
- Security database references:
- In Mitre's CVE dictionary: CVE-2016-9941, CVE-2016-9942.
- More information:
It was discovered that there were two vulnerabilities in libvncserver, a library to create/embed a VNC server:
Fix a heap-based buffer overflow that allows remote servers to cause a denial of service via a crafted FramebufferUpdate message containing a subrectangle outside of the drawing area.
Fix a heap-based buffer overflow that allow remote servers to cause a denial of service via a crafted FramebufferUpdate message with the
Ultratype tile such that the LZO decompressed payload exceeds the size of the tile dimensions.
For Debian 7
Wheezy, these issues have been fixed in libvncserver version 0.9.9+dfsg-1+deb7u2.
We recommend that you upgrade your libvncserver packages.