Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 634788 - <net-misc/tigervnc-1.8.0: Multiple vulnerabilities (CVE-2017-{7392,7393,7394,7395,7396})
Summary: <net-misc/tigervnc-1.8.0: Multiple vulnerabilities (CVE-2017-{7392,7393,7394,...
Status: RESOLVED DUPLICATE of bug 614742
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B2 [noglsa cve]
Keywords:
Depends on:
Blocks: CVE-2016-10207
  Show dependency tree
 
Reported: 2017-10-19 16:26 UTC by GLSAMaker/CVETool Bot
Modified: 2018-01-09 00:41 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2017-10-19 16:26:57 UTC
CVE-2017-7396 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-7396):
  In TigerVNC 1.7.1 (CConnection.cxx CConnection::CConnection), an
  unauthenticated client can cause a small memory leak in the server.

CVE-2017-7395 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-7395):
  In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing
  an integer overflow, an authenticated client can crash the server.

CVE-2017-7394 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-7394):
  In TigerVNC 1.7.1 (SSecurityPlain.cxx SSecurityPlain::processMsg),
  unauthenticated users can crash the server by sending long usernames.

CVE-2017-7393 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-7393):
  In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an
  authenticated client can cause a double free, leading to denial of service
  or potentially code execution.

CVE-2017-7392 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-7392):
  In TigerVNC 1.7.1 (SSecurityVeNCrypt.cxx
  SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a
  small memory leak in the server.


@Maintainer could you please confirm if we are affected by these vulnerabilities?

Should be call for 1.8.0 stabilization?

Thank you
Comment 1 otakuto.gentoo 2017-10-20 15:53:24 UTC
I confirmed that these vulnerabilities affect to all architectures.
Yes, at least hhpa should Stabilize. Also remove 1.7.1.
Comment 2 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-11-24 22:30:45 UTC
Added to existing glsa request.
Comment 3 Aaron Bauman (RETIRED) gentoo-dev 2018-01-09 00:41:19 UTC

*** This bug has been marked as a duplicate of bug 614742 ***