TEMP-0000000-70147B

NameTEMP-0000000-70147B
DescriptionMemory corruption
SourceAutomatically generated temporary name. Not for external reference.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libvncserver (PTS)jessie, jessie (lts)0.9.9+dfsg2-6.1+deb8u8fixed
stretch (security)0.9.11+dfsg-1.3~deb9u6fixed
stretch (lts), stretch0.9.11+dfsg-1.3~deb9u7fixed
buster0.9.11+dfsg-1.3+deb10u4fixed
buster (security)0.9.11+dfsg-1.3+deb10u5fixed
bullseye0.9.13+dfsg-2+deb11u1fixed
trixie, sid, bookworm0.9.14+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libvncserversourcesqueeze0.9.7-2+deb6u2
libvncserversource(unstable)0.9.8-1

Notes

workaround entry for DLA-380-1 until/if CVE assigned
https://github.com/LibVNC/libvncserver/commit/804335f9d296440bb708ca844f5d89b58b50b0c6
CVE Request: https://www.openwall.com/lists/oss-security/2015/09/03/8
https://bugzilla.redhat.com/show_bug.cgi?id=706087#c1 notes that the fix breaks ABI

Search for package or bug name: Reporting problems