Rapid7 Vulnerability & Exploit Database

Gentoo Linux: CVE-2011-0904: Multiple packages, Multiple vulnerabilities fixed in 2011

Back to Search

Gentoo Linux: CVE-2011-0904: Multiple packages, Multiple vulnerabilities fixed in 2011

Severity
4
CVSS
(AV:N/AC:M/Au:S/C:N/I:N/A:P)
Published
05/10/2011
Created
07/25/2018
Added
10/30/2017
Modified
10/30/2017

Description

The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when raw encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via a large (1) X position or (2) Y position value in a framebuffer update request that triggers an out-of-bounds memory access, related to the rfbTranslateNone and rfbSendRectEncodingRaw functions.

Solution(s)

  • gentoo-linux-upgrade-app-admin-syslog-ng
  • gentoo-linux-upgrade-app-misc-ca-certificates
  • gentoo-linux-upgrade-app-office-gnucash
  • gentoo-linux-upgrade-dev-db-unixodbc
  • gentoo-linux-upgrade-dev-libs-xmlsec
  • gentoo-linux-upgrade-dev-php-pear-mail
  • gentoo-linux-upgrade-dev-php-pear-pear
  • gentoo-linux-upgrade-dev-util-oprofile
  • gentoo-linux-upgrade-dev-util-qt-creator
  • gentoo-linux-upgrade-dev-vcs-gitolite
  • gentoo-linux-upgrade-games-sports-racer-bin
  • gentoo-linux-upgrade-gnome-base-gdm
  • gentoo-linux-upgrade-media-libs-fmod
  • gentoo-linux-upgrade-media-libs-xine-lib
  • gentoo-linux-upgrade-media-sound-lastfmplayer
  • gentoo-linux-upgrade-net-analyzer-sflowtool
  • gentoo-linux-upgrade-net-libs-libsoup
  • gentoo-linux-upgrade-net-libs-webkit-gtk
  • gentoo-linux-upgrade-net-misc-mrouted
  • gentoo-linux-upgrade-net-misc-rsync
  • gentoo-linux-upgrade-net-misc-vino
  • gentoo-linux-upgrade-sys-apps-shadow
  • gentoo-linux-upgrade-sys-cluster-resource-agents
  • gentoo-linux-upgrade-sys-fs-lvm2
  • gentoo-linux-upgrade-x11-apps-xrdb

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;