From 4a985e3138ad3f14d8fea8db6d25f4f77fc33d28 Mon Sep 17 00:00:00 2001 From: Thomas Deutschmann Date: Thu, 11 Jan 2018 23:47:00 +0100 Subject: Add GLSA 201801-13 --- glsa-201801-13.xml | 67 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 67 insertions(+) create mode 100644 glsa-201801-13.xml (limited to 'glsa-201801-13.xml') diff --git a/glsa-201801-13.xml b/glsa-201801-13.xml new file mode 100644 index 00000000..e744cfc5 --- /dev/null +++ b/glsa-201801-13.xml @@ -0,0 +1,67 @@ + + + + TigerVNC: Multiple vulnerabilities + Multiple vulnerabilities have been found in TigerVNC, the worst of + which may lead to arbitrary code execution. + + tigervnc + 2018-01-11 + 2018-01-11: 1 + 614742 + 636396 + local, remote + + + 1.8.0 + 1.8.0 + + + +

TigerVNC is a high-performance VNC server/client.

+
+ +

Multiple vulnerabilities have been discovered in TigerVNC. Please review + the referenced CVE Identifiers for details. +

+
+ +

An attacker could execute arbitrary code or cause a Denial of Service + condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All TigerVNC users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-misc/tigervnc-1.8.0" + + +
+ + + CVE-2016-10207 + + + CVE-2017-7392 + + + CVE-2017-7393 + + + CVE-2017-7394 + + + CVE-2017-7395 + + + CVE-2017-7396 + + + chrisadr + b-man +
-- cgit v1.2.3-65-gdbad