Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.831392
Categoría:Mandrake Local Security Checks
Título:Mandriva Update for vino MDVSA-2011:087 (vino)
Resumen:The remote host is missing an update for the 'vino'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'vino'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Multiple vulnerabilities has been found and corrected in vino:

The rfbSendFramebufferUpdate function in
server/libvncserver/rfbserver.c in vino-server in Vino 2.x before
2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before
3.1.1, when raw encoding is used, allows remote authenticated users to
cause a denial of service (daemon crash) via a large (1) X position or
(2) Y position value in a framebuffer update request that triggers
an out-of-bounds memory access, related to the rfbTranslateNone and
rfbSendRectEncodingRaw functions (CVE-2011-0904).

The rfbSendFramebufferUpdate function in
server/libvncserver/rfbserver.c in vino-server in Vino 2.x before
2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before
3.1.1, when tight encoding is used, allows remote authenticated users
to cause a denial of service (daemon crash) via crafted dimensions
in a framebuffer update request that triggers an out-of-bounds read
operation (CVE-2011-0905).

The updated packages have been upgraded to 2.28.3 which is not
vulnerable to these issues.

Affected Software/OS:
vino on Mandriva Linux 2010.1,
Mandriva Linux 2010.1/X86_64

Solution:
Please Install the Updated Packages.

CVSS Score:
3.5

CVSS Vector:
AV:N/AC:M/Au:S/C:N/I:N/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-0904
BugTraq ID: 47681
http://www.securityfocus.com/bid/47681
Debian Security Information: DSA-2238 (Google Search)
http://www.debian.org/security/2011/dsa-2238
http://www.mandriva.com/security/advisories?name=MDVSA-2011:087
RedHat Security Advisories: RHSA-2013:0169
http://rhn.redhat.com/errata/RHSA-2013-0169.html
http://secunia.com/advisories/44410
http://secunia.com/advisories/44463
SuSE Security Announcement: SUSE-SR:2011:009 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
http://www.ubuntu.com/usn/usn-1128-1/
http://www.vupen.com/english/advisories/2011/1144
XForce ISS Database: vino-input-dos(67243)
https://exchange.xforce.ibmcloud.com/vulnerabilities/67243
Common Vulnerability Exposure (CVE) ID: CVE-2011-0905
XForce ISS Database: vino-framebuffer-dos(67244)
https://exchange.xforce.ibmcloud.com/vulnerabilities/67244
CopyrightCopyright (C) 2011 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.