Debian Security Advisory

DLA-777-1 libvncserver -- LTS security update

Date Reported:
03 Jan 2017
Affected Packages:
libvncserver
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2016-9941, CVE-2016-9942.
More information:

It was discovered that there were two vulnerabilities in libvncserver, a library to create/embed a VNC server:

  • CVE-2016-9941

    Fix a heap-based buffer overflow that allows remote servers to cause a denial of service via a crafted FramebufferUpdate message containing a subrectangle outside of the drawing area.

  • CVE-2016-9942

    Fix a heap-based buffer overflow that allow remote servers to cause a denial of service via a crafted FramebufferUpdate message with the Ultra type tile such that the LZO decompressed payload exceeds the size of the tile dimensions.

For Debian 7 Wheezy, these issues have been fixed in libvncserver version 0.9.9+dfsg-1+deb7u2.

We recommend that you upgrade your libvncserver packages.