[Buildroot] [PATCH] libvncserver: add upstream security fix for CVE-2018-7225

Peter Korsgaard peter at korsgaard.com
Tue Jul 17 07:31:30 UTC 2018


>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:

 > Fixes CVE-2018-7225 - An issue was discovered in LibVNCServer through
 > 0.9.11.  rfbProcessClientNormalMessage() in rfbserver.c does not sanitize
 > msg.cct.length, leading to access to uninitialized and potentially sensitive
 > data or possibly unspecified other impact (e.g., an integer overflow) via
 > specially crafted VNC packets.

 > Signed-off-by: Peter Korsgaard <peter at korsgaard.com>

Committed to 2018.05.x, thanks.

-- 
Bye, Peter Korsgaard


More information about the buildroot mailing list