![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.831392 |
Category: | Mandrake Local Security Checks |
Title: | Mandriva Update for vino MDVSA-2011:087 (vino) |
Summary: | The remote host is missing an update for the 'vino'; package(s) announced via the referenced advisory. |
Description: | Summary: The remote host is missing an update for the 'vino' package(s) announced via the referenced advisory. Vulnerability Insight: Multiple vulnerabilities has been found and corrected in vino: The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when raw encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via a large (1) X position or (2) Y position value in a framebuffer update request that triggers an out-of-bounds memory access, related to the rfbTranslateNone and rfbSendRectEncodingRaw functions (CVE-2011-0904). The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when tight encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via crafted dimensions in a framebuffer update request that triggers an out-of-bounds read operation (CVE-2011-0905). The updated packages have been upgraded to 2.28.3 which is not vulnerable to these issues. Affected Software/OS: vino on Mandriva Linux 2010.1, Mandriva Linux 2010.1/X86_64 Solution: Please Install the Updated Packages. CVSS Score: 3.5 CVSS Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2011-0904 BugTraq ID: 47681 http://www.securityfocus.com/bid/47681 Debian Security Information: DSA-2238 (Google Search) http://www.debian.org/security/2011/dsa-2238 http://www.mandriva.com/security/advisories?name=MDVSA-2011:087 RedHat Security Advisories: RHSA-2013:0169 http://rhn.redhat.com/errata/RHSA-2013-0169.html http://secunia.com/advisories/44410 http://secunia.com/advisories/44463 SuSE Security Announcement: SUSE-SR:2011:009 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html http://www.ubuntu.com/usn/usn-1128-1/ http://www.vupen.com/english/advisories/2011/1144 XForce ISS Database: vino-input-dos(67243) https://exchange.xforce.ibmcloud.com/vulnerabilities/67243 Common Vulnerability Exposure (CVE) ID: CVE-2011-0905 XForce ISS Database: vino-framebuffer-dos(67244) https://exchange.xforce.ibmcloud.com/vulnerabilities/67244 |
Copyright | Copyright (C) 2011 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |