Red Hat Security Advisory 2017-2258-01

Discussion in 'News Aggregator' started by Packet Storm, 2 Aug 2017.

  1. Packet Storm

    Packet Storm Guest

    Red Hat Security Advisory 2017-2258-01 - The gtk-vnc packages provide a VNC viewer widget for GTK. The gtk-vnc widget is built by using co-routines, which allows the widget to be completely asynchronous while remaining single-threaded. The following packages have been upgraded to a later upstream version: gtk-vnc. Security Fix: It was found that gtk-vnc lacked proper bounds checking while processing messages using RRE, hextile, or copyrect encodings. A remote malicious VNC server could use this flaw to crash VNC viewers which are based on the gtk-vnc library.

    Continue reading...
     

Share This Page

Loading...