libvncserver (SL6, SL7)

Synopsis: Moderate: libvncserver security update
Advisory ID: SLSA-2014:1826-1
Issue Date: 2014-11-11
CVE Numbers: CVE-2014-6051
CVE-2014-6052
CVE-2014-6053
CVE-2014-6054
CVE-2014-6055

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way screen sizes were handled by LibVNCServer. A malicious
VNC server could use this flaw to cause a client to crash or, potentially,
execute arbitrary code in the client. (CVE-2014-6051)

A NULL pointer dereference flaw was found in LibVNCServer’s framebuffer
setup. A malicious VNC server could use this flaw to cause a VNC client to
crash. (CVE-2014-6052)

A NULL pointer dereference flaw was found in the way LibVNCServer handled
certain ClientCutText message. A remote attacker could use this flaw to
crash the VNC server by sending a specially crafted ClientCutText message
from a VNC client. (CVE-2014-6053)

A divide-by-zero flaw was found in the way LibVNCServer handled the
scaling factor when it was set to “0”. A remote attacker could use this
flaw to crash the VNC server using a malicious VNC client. (CVE-2014-6054)

Two stack-based buffer overflow flaws were found in the way LibVNCServer
handled file transfers. A remote attacker could use this flaw to crash the
VNC server using a malicious VNC client. (CVE-2014-6055)

All running applications linked against libvncserver must be restarted for
this update to take effect.

SL6
x86_64
libvncserver-0.9.7-7.el6_6.1.x86_64.rpm
libvncserver-debuginfo-0.9.7-7.el6_6.1.x86_64.rpm
libvncserver-0.9.7-7.el6_6.1.i686.rpm
libvncserver-debuginfo-0.9.7-7.el6_6.1.i686.rpm
libvncserver-devel-0.9.7-7.el6_6.1.i686.rpm
libvncserver-devel-0.9.7-7.el6_6.1.x86_64.rpm
i386
libvncserver-0.9.7-7.el6_6.1.i686.rpm
libvncserver-debuginfo-0.9.7-7.el6_6.1.i686.rpm
libvncserver-devel-0.9.7-7.el6_6.1.i686.rpm
SL7
x86_64
libvncserver-0.9.9-9.el7_0.1.i686.rpm
libvncserver-0.9.9-9.el7_0.1.x86_64.rpm
libvncserver-debuginfo-0.9.9-9.el7_0.1.i686.rpm
libvncserver-debuginfo-0.9.9-9.el7_0.1.x86_64.rpm
libvncserver-devel-0.9.9-9.el7_0.1.i686.rpm
libvncserver-devel-0.9.9-9.el7_0.1.x86_64.rpm

– Scientific Linux Development Team