Lucene search

K
mageiaGentoo FoundationMGASA-2023-0321
HistoryNov 20, 2023 - 1:04 p.m.

Updated tigervnc packages fix security vulnerabilities

2023-11-2013:04:11
Gentoo Foundation
advisories.mageia.org
18
tigervnc
security vulnerabilities
patch
oob write
use-after-free
unix

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.9%

The updated packages fix security vulnerabilities: OOB write in XIChangeDeviceProperty/RRChangeOutputProperty. (CVE-2023-5367) Use-after-free bug in DestroyWindow. (CVE-2023-5380)

OSVersionArchitecturePackageVersionFilename
Mageia8noarchtigervnc< 1.11.0-4.4tigervnc-1.11.0-4.4.mga8
Mageia9noarchtigervnc< 1.13.1-2.1tigervnc-1.13.1-2.1.mga9

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.9%