Synopsis:          Moderate: libvncserver security update
Advisory ID:       SLSA-2014:1826-1
Issue Date:        2014-11-11
CVE Numbers:       CVE-2014-6051
                   CVE-2014-6052
                   CVE-2014-6053
                   CVE-2014-6054
                   CVE-2014-6055
--

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way screen sizes were handled by LibVNCServer. A malicious
VNC server could use this flaw to cause a client to crash or, potentially,
execute arbitrary code in the client. (CVE-2014-6051)

A NULL pointer dereference flaw was found in LibVNCServer's framebuffer
setup. A malicious VNC server could use this flaw to cause a VNC client to
crash. (CVE-2014-6052)

A NULL pointer dereference flaw was found in the way LibVNCServer handled
certain ClientCutText message. A remote attacker could use this flaw to
crash the VNC server by sending a specially crafted ClientCutText message
from a VNC client. (CVE-2014-6053)

A divide-by-zero flaw was found in the way LibVNCServer handled the
scaling factor when it was set to "0". A remote attacker could use this
flaw to crash the VNC server using a malicious VNC client. (CVE-2014-6054)

Two stack-based buffer overflow flaws were found in the way LibVNCServer
handled file transfers. A remote attacker could use this flaw to crash the
VNC server using a malicious VNC client. (CVE-2014-6055)

All running applications linked against libvncserver must be restarted for
this update to take effect.
--

SL6
  x86_64
    libvncserver-0.9.7-7.el6_6.1.x86_64.rpm
    libvncserver-debuginfo-0.9.7-7.el6_6.1.x86_64.rpm
    libvncserver-0.9.7-7.el6_6.1.i686.rpm
    libvncserver-debuginfo-0.9.7-7.el6_6.1.i686.rpm
    libvncserver-devel-0.9.7-7.el6_6.1.i686.rpm
    libvncserver-devel-0.9.7-7.el6_6.1.x86_64.rpm
  i386
    libvncserver-0.9.7-7.el6_6.1.i686.rpm
    libvncserver-debuginfo-0.9.7-7.el6_6.1.i686.rpm
    libvncserver-devel-0.9.7-7.el6_6.1.i686.rpm
SL7
  x86_64
    libvncserver-0.9.9-9.el7_0.1.i686.rpm
    libvncserver-0.9.9-9.el7_0.1.x86_64.rpm
    libvncserver-debuginfo-0.9.9-9.el7_0.1.i686.rpm
    libvncserver-debuginfo-0.9.9-9.el7_0.1.x86_64.rpm
    libvncserver-devel-0.9.9-9.el7_0.1.i686.rpm
    libvncserver-devel-0.9.9-9.el7_0.1.x86_64.rpm

- Scientific Linux Development Team