Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 250314
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Steven Susbauer <stupendoussteve@hotmail.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 250314 depends on: Show dependency tree
Bug 250314 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-12-08 19:39 0000
Description:
A vulnerability has been discovered in Vinagre, which can be exploited by
malicious people to compromise a user's system.

The vulnerability is caused due to a format string error within the
"vinagre_utils_show_error()" function in src/vinagre-utils.c. This can be
exploited by e.g. tricking a user into opening a specially crafted .vnc file.

Successful exploitation may allow the execution of arbitrary code.

The vulnerability is confirmed in version 2.24.0. Other versions may also be
affected.

Ref: http://ftp.gnome.org/pub/GNOME/sources/vinagre/0.5/vinagre-0.5.2.changes
http://ftp.gnome.org/pub/GNOME/sources/vinagre/2.24/vinagre-2.24.2.changes

Reproducible: Always

------- Comment #1 From Mart Raudsepp 2008-12-10 03:14:11 0000 -------
vinagre 0.5.2 and 2.24.2 are in portage tree now - they contain the obvious
fix.

Arches, please stabilize net-misc/vinagre-0.5.2

------- Comment #2 From Tobias Heinlein 2008-12-10 17:27:37 0000 -------
amd64 stable

------- Comment #3 From Markus Meier 2008-12-10 22:18:09 0000 -------
x86 stable

------- Comment #4 From Jeroen Roovers 2008-12-11 17:57:03 0000 -------
Stable for HPPA. Looks like 2.24.1 can be removed immediately.

------- Comment #5 From Brent Baude 2008-12-11 21:24:18 0000 -------
ppc64 done

------- Comment #6 From Friedrich Oslage 2008-12-13 11:03:41 0000 -------
sparc stable

------- Comment #7 From Tobias Scherbaum 2008-12-13 13:48:44 0000 -------
ppc stable

------- Comment #8 From Raúl Porcel 2008-12-13 17:30:58 0000 -------
alpha/ia64 stable

------- Comment #9 From Tobias Heinlein 2008-12-13 20:31:13 0000 -------
GLSA request filed.

------- Comment #10 From Robert Buchholz 2008-12-18 16:33:27 0000 -------
CVE-2008-5660 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5660):
  Format string vulnerability in the vinagre_utils_show_error function
  (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2 and 2.x before
  2.24.2 might allow remote attackers to execute arbitrary code via a
  crafted URI or VNC server response.

------- Comment #11 From Pierre-Yves Rofes 2009-03-06 22:05:06 0000 -------
GLSA 200903-01

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug