[Buildroot] [PATCH] libvncserver: add upstream security fix for CVE-2018-7225
peter at korsgaard.com
Sun Jun 17 15:52:15 UTC 2018
>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:
> Fixes CVE-2018-7225 - An issue was discovered in LibVNCServer through
> 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize
> msg.cct.length, leading to access to uninitialized and potentially sensitive
> data or possibly unspecified other impact (e.g., an integer overflow) via
> specially crafted VNC packets.
> Signed-off-by: Peter Korsgaard <peter at korsgaard.com>
Committed to 2018.02.x, thanks.
Bye, Peter Korsgaard
More information about the buildroot