漏洞信息详情
TigerVNC 代码问题漏洞
漏洞简介
TigerVNC是一款VNC(虚拟网络控制台)服务器和客户端软件。
TigerVNC 1.10.1之前版本中的‘CMsgReader :: readSetCursor’函数存在代码问题漏洞,该漏洞源于程序没有充分清理PixelFormat。远程攻击者可利用该漏洞在系统上执行任意代码。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/TigerVNC/tigervnc/releases/tag/v1.10.1
参考网址
来源:github.com
链接:https://github.com/CendioOssman/tigervnc/commit/05e28490873a861379c943bf616614b78b558b89
来源:www.openwall.com
链接:https://www.openwall.com/lists/oss-security/2019/12/20/2
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00039.html
来源:github.com
链接:https://github.com/TigerVNC/tigervnc/releases/tag/v1.10.1
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2020/suse-su-20200266-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2020/suse-su-20200113-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2020/suse-su-20200112-1.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.1356/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.0176/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.0362/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/TigerVNC-multiple-vulnerabilities-31231
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/157272/Red-Hat-Security-Advisory-2020-1497-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159340/Red-Hat-Security-Advisory-2020-3875-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3356/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-15695
受影响实体
暂无
补丁
- TigerVNC 缓冲区错误漏洞的修复措施<!--2019-12-23-->
还没有评论,来说两句吧...