|
|
Log in / Subscribe / Register

Gentoo alert 202407-14 (TigerVNC)

From:  glsamaker@gentoo.org
To:  gentoo-announce@lists.gentoo.org
Subject:  [gentoo-announce] [ GLSA 202407-14 ] TigerVNC: Multiple Vulnerabilities
Date:  Fri, 05 Jul 2024 08:05:24 -0000
Message-ID:  <172016672433.7.16202822521113211787@3f85d36892cf>

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202407-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: TigerVNC: Multiple Vulnerabilities Date: July 05, 2024 Bugs: #700464 ID: 202407-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in TigerVNC, the worst of which could lead to remote code execution. Background ========== TigerVNC is a high-performance VNC server/client. Affected packages ================= Package Vulnerable Unaffected ----------------- ------------ ------------ net-misc/tigervnc < 1.12.0-r2 >= 1.12.0-r2 Description =========== Multiple vulnerabilities have been discovered in TigerVNC. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All TigerVNC users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/tigervnc-1.12.0-r2" References ========== [ 1 ] CVE-2019-15691 https://nvd.nist.gov/vuln/detail/CVE-2019-15691 [ 2 ] CVE-2019-15692 https://nvd.nist.gov/vuln/detail/CVE-2019-15692 [ 3 ] CVE-2019-15694 https://nvd.nist.gov/vuln/detail/CVE-2019-15694 [ 4 ] CVE-2019-15695 https://nvd.nist.gov/vuln/detail/CVE-2019-15695 [ 5 ] CVE-2020-26117 https://nvd.nist.gov/vuln/detail/CVE-2020-26117 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202407-14 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmaHqUQACgkQFMQkOaVy +9kbdA/+PVQmUiDzPIptEzU85/7rQeXN2qKtN4MuZhfJNJj1xQu21ZSPCqBvzXSh rjn9kcchYi1OHHaTG3Zzpw9rLf/wCeqFfcmXgD8UcCEm6xfuQeB2iWhlCGivOyuO gL9IAeXWxBlXsDT7692JM2jHDcry5i5GKmy+gmi4I02LPfLQCXDBnxSyUXAnirQs P47TxXwxphrFqSezyhkq8IFx9+xC+lpBvP+Itw7Pg+YNtL7aTfw9tnTICtVr2S3u FQ68NSXwbSWSTUIoaV/5S6c8orShsM1Hx7g/r2pxVc7m1vTsXTB3OU6Dh/6XNndB hyPb0/GFS0rDIKjbIQmdEbqSEAzNFmbFyWXgmVFimQwl8hF6hDWzhue8SyS/YZt/ 4t9jxz6b1CVx8iCcxWfVtXQjJlTcdf4Rxtg7fR3XPLsQ0daSG/WZr9eIZYi0F8CK e2dmLYE9CxOFwMe+Nfqis7MW1meV6Yw3lcLETjTZRzSODdsA3HU8BDbvZzQnpNVp rS1ojHvJWdOG4mmikh/X8VhafQA7PolVKhZb8TXqUM/d9XvZGZs8Lqj39zURSS2N s319R99pESPK/++BTYpYK8lfJ0YjBg8fxAaMjmNmZla7h/FuEf6FEcPNi+RfuO7l BAfw126Qx5QZwMeDnFfhDM+WbTZSFSNsYK5vdvjjojVZAb9xwFE= =3uuF -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds