Go to:
Gentoo Home
Documentation
Forums
Lists
Bugs
Planet
Store
Wiki
Get Gentoo!
Gentoo's Bugzilla – Attachment 634764 Details for
Bug 701820
net-misc/ssvnc: multiple vulnerabilities (CVE-2018-{20020,20021,20022,20024})
Home
|
New
–
[Ex]
|
Browse
|
Search
|
Privacy Policy
|
[?]
|
Reports
|
Requests
|
Help
|
New Account
|
Log In
[x]
|
Forgot Password
Login:
[x]
[patch]
CVE-2018-20022 Patch
ssvnc-1.0.29-libvncclient_CVE-2018-20022.patch (text/plain), 979 bytes, created by
David Turner
on 2020-04-26 21:49:50 UTC
(
hide
)
Description:
CVE-2018-20022 Patch
Filename:
MIME Type:
Creator:
David Turner
Created:
2020-04-26 21:49:50 UTC
Size:
979 bytes
patch
obsolete
>Description: CVE-2018-20022 > multiple weaknesses CWE-665: Improper Initialization vulnerability in VNC > client code that allows attacker to read stack memory and can be abuse for > information disclosure. Combined with another vulnerability, it can be used > to leak stack memory layout and in bypassing ASLR >--- > >Author: Abhijith PA <abhijith@debian.org> >Origin: https://github.com/LibVNC/libvncserver/commit/2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 >Bug: https://github.com/LibVNC/libvncserver/issues/252 >Bug-Debian: https://bugs.debian.org/916941 >Last-Update: 2018-12-23 > >--- a/vnc_unixsrc/vncviewer/rfbproto.c >+++ b/vnc_unixsrc/vncviewer/rfbproto.c >@@ -2447,6 +2447,7 @@ > } > } > >+ memset(&ke, 0, sizeof(ke)); > ke.type = rfbKeyEvent; > ke.down = down ? 1 : 0; > ke.key = Swap32IfLE(key); >@@ -2480,6 +2481,7 @@ > return True; > } > >+ memset(&cct, 0, sizeof(cct)); > cct.type = rfbClientCutText; > cct.length = Swap32IfLE((unsigned int) len); > currentMsg = rfbClientCutText;
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 701820
:
634760
|
634762
| 634764 |
634766
|
634768