Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.871869
Categoría:Red Hat Local Security Checks
Título:RedHat Update for gtk-vnc RHSA-2017:2258-01
Resumen:The remote host is missing an update for the 'gtk-vnc'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'gtk-vnc'
package(s) announced via the referenced advisory.

Vulnerability Insight:
The gtk-vnc packages provide a VNC viewer
widget for GTK. The gtk-vnc widget is built by using co-routines, which allows
the widget to be completely asynchronous while remaining single-threaded. The
following packages have been upgraded to a later upstream version: gtk-vnc
(0.7.0). (BZ#1416783) Security Fix(es): * It was found that gtk-vnc lacked
proper bounds checking while processing messages using RRE, hextile, or copyrect
encodings. A remote malicious VNC server could use this flaw to crash VNC
viewers which are based on the gtk-vnc library. (CVE-2017-5884) * An integer
overflow flaw was found in gtk-vnc. A remote malicious VNC server could use this
flaw to crash VNC viewers which are based on the gtk-vnc library.
(CVE-2017-5885) Additional Changes: For detailed information on changes in this
release, see the Red Hat Enterprise Linux 7.4 Release Notes linked from the
References section.

Affected Software/OS:
gtk-vnc on Red Hat Enterprise Linux Server (v. 7)

Solution:
Please Install the Updated Packages.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-5884
96016
http://www.securityfocus.com/bid/96016
FEDORA-2017-ab04a91edd
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LGPQ5MQR6SN4DYTEFACHP2PP5RR26KYK/
RHSA-2017:2258
https://access.redhat.com/errata/RHSA-2017:2258
[oss-security] 20170203 CVE request for two input validation flaws in gtk-vnc
http://www.openwall.com/lists/oss-security/2017/02/03/5
[oss-security] 20170204 Re: CVE request for two input validation flaws in gtk-vnc
http://www.openwall.com/lists/oss-security/2017/02/05/5
https://bugzilla.gnome.org/show_bug.cgi?id=778048
https://git.gnome.org/browse/gtk-vnc/commit/?id=ea0386933214c9178aaea9f2f85049ea3fa3e14a
Common Vulnerability Exposure (CVE) ID: CVE-2017-5885
https://bugzilla.gnome.org/show_bug.cgi?id=778050
https://git.gnome.org/browse/gtk-vnc/commit/?id=c8583fd3783c5b811590fcb7bae4ce6e7344963e
CopyrightCopyright (C) 2017 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.