File _patchinfo of Package patchinfo.13372
<patchinfo incident="13372">
<issue tracker="cve" id="2017-18922"/>
<issue tracker="cve" id="2020-14397"/>
<issue tracker="cve" id="2020-14401"/>
<issue tracker="cve" id="2020-14400"/>
<issue tracker="cve" id="2019-20839"/>
<issue tracker="cve" id="2020-14402"/>
<issue tracker="cve" id="2020-14398"/>
<issue tracker="cve" id="2020-14399"/>
<issue tracker="cve" id="2018-21247"/>
<issue tracker="cve" id="2019-20840"/>
<issue tracker="bnc" id="1173875">VUL-0: CVE-2019-20839: LibVNCServer: buffer overflow in ConnectClientToUnixSock()</issue>
<issue tracker="bnc" id="1173700">VUL-0: CVE-2020-14397: LibVNCServer: NULL pointer dereference in libvncserver/rfbregion.c</issue>
<issue tracker="bnc" id="1173743">VUL-1: CVE-2020-14399: LibVNCServer: Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c.</issue>
<issue tracker="bnc" id="1173694">VUL-0: CVE-2020-14401: LibVNCServer: potential integer overflows in libvncserver/scale.c</issue>
<issue tracker="bnc" id="1173691">VUL-0: CVE-2020-14400: LibVNCServer: Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c.</issue>
<issue tracker="bnc" id="1173477">VUL-0: CVE-2017-18922: LibVNCServer: preauth buffer overwrite</issue>
<issue tracker="bnc" id="1173876">VUL-0: CVE-2019-20840: LibVNCServer: unaligned accesses in hybiReadAndDecode can lead to denial of service</issue>
<issue tracker="bnc" id="1173701">VUL-0: CVE-2020-14402,CVE-2020-14403,CVE-2020-14404: LibVNCServer: out-of-bounds access via encodings.</issue>
<issue tracker="bnc" id="1173880">VUL-0: CVE-2020-14398: LibVNCServer: improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c</issue>
<issue tracker="bnc" id="1173874">VUL-0: CVE-2018-21247: LibVNCServer: uninitialized memory contents are vulnerable to Information leak</issue>
<packager>pgajdos</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for LibVNCServer</summary>
<description>This update for LibVNCServer fixes the following issues:
- security update
- added patches
fix CVE-2018-21247 [bsc#1173874], uninitialized memory contents are vulnerable to Information leak
+ LibVNCServer-CVE-2018-21247.patch
fix CVE-2019-20839 [bsc#1173875], buffer overflow in ConnectClientToUnixSock()
+ LibVNCServer-CVE-2019-20839.patch
fix CVE-2019-20840 [bsc#1173876], unaligned accesses in hybiReadAndDecode can lead to denial of service
+ LibVNCServer-CVE-2019-20840.patch
fix CVE-2020-14398 [bsc#1173880], improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c
+ LibVNCServer-CVE-2020-14398.patch
fix CVE-2020-14397 [bsc#1173700], NULL pointer dereference in libvncserver/rfbregion.c
+ LibVNCServer-CVE-2020-14397.patch
fix CVE-2020-14399 [bsc#1173743], Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c.
+ LibVNCServer-CVE-2020-14399.patch
fix CVE-2020-14400 [bsc#1173691], Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c.
+ LibVNCServer-CVE-2020-14400.patch
fix CVE-2020-14401 [bsc#1173694], potential integer overflows in libvncserver/scale.c
+ LibVNCServer-CVE-2020-14401.patch
fix CVE-2020-14402 [bsc#1173701], out-of-bounds access via encodings.
+ LibVNCServer-CVE-2020-14402,14403,14404.patch
fix CVE-2017-18922 [bsc#1173477], preauth buffer overwrite
This update was imported from the SUSE:SLE-15:Update update project.</description>
</patchinfo>