Lucene search

K
mageiaGentoo FoundationMGASA-2022-0363
HistoryOct 08, 2022 - 11:22 p.m.

Updated libvncserver packages fix security vulnerability

2022-10-0823:22:22
Gentoo Foundation
advisories.mageia.org
25
libvncserver memory leak unix cve-2020-29260 fix security

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

30.2%

libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup(). (CVE-2020-29260)

OSVersionArchitecturePackageVersionFilename
Mageia8noarchlibvncserver< 0.9.13-1.1libvncserver-0.9.13-1.1.mga8
Mageia8noarchitalc< 3.0.3-6.1italc-3.0.3-6.1.mga8

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

30.2%