Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 133219 - net-misc/vnc: 4.1.2 released, fixes security vulnerability
Summary: net-misc/vnc: 4.1.2 released, fixes security vulnerability
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Other
: High minor (vote)
Assignee: Gentoo Security
URL: http://realvnc.com/
Whiteboard: B4 [ebuild] DerCorny
Keywords:
: 134819 (view as bug list)
Depends on:
Blocks:
 
Reported: 2006-05-13 10:47 UTC by Nathan Blomquist
Modified: 2006-05-29 13:22 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Nathan Blomquist 2006-05-13 10:47:50 UTC
RealVNC released a new version of VNC.  This new version is 4.1.2.  It fixes a security vulnerability that would allow an attacker to login without a password.

I was unable to find a source tar ball.  They provide only binaries at this point.

http://realvnc.com/

I did not see any more detailed information on specifics of the bug.
Comment 1 Stefan Cornelius (RETIRED) gentoo-dev 2006-05-14 05:37:17 UTC
Opening bug to public, since the information comes from the package's homepage anyways.

Aliz, please have a look and provide new ebuilds, thank you.
Comment 2 Stefan Cornelius (RETIRED) gentoo-dev 2006-05-14 05:39:39 UTC
sorry for bugspam, forgot to edit some bug details
Comment 3 Mike Auty (RETIRED) gentoo-dev 2006-05-14 06:43:37 UTC
Please note this security vulnerability only affects realvnc 4.1.x, and at the moment I believe the version in portage is 4.0.x.  If further specifics concerning the bug are required, please let me know...

As such it isn't as critical to get a security fix out for it, however since we're at least a couple versions behind it would still be nice...
Comment 4 Stefan Cornelius (RETIRED) gentoo-dev 2006-05-14 06:49:32 UTC
Where do you have that information from? The realvnc homepage is not very verbose about this issue?
Comment 5 Mike Auty (RETIRED) gentoo-dev 2006-05-14 06:57:49 UTC
Further information can be found at http://www.intelliadmin.com/blog/2006/05/vnc-flaw-proof-of-concept.html.  These are the people who initially reported the flaw.
Comment 6 Stefan Cornelius (RETIRED) gentoo-dev 2006-05-14 09:12:44 UTC
we are not affected, thanks to ikelos for the headsup.
Comment 7 Jakub Moc (RETIRED) gentoo-dev 2006-05-29 13:22:31 UTC
*** Bug 134819 has been marked as a duplicate of this bug. ***