Index: security/vuxml/vuln.xml =================================================================== --- security/vuxml/vuln.xml (revision 423460) +++ security/vuxml/vuln.xml (working copy) @@ -58,6 +58,40 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + libvncserver -- multiple security vulnerabilities + + + libvncserver + 0.9.10 + + + + +

Nicolas Ruff reports:

+
+

Integer overflow in MallocFrameBuffer() on client side.

+

Lack of malloc() return value checking on client side.

+

Server crash on a very large ClientCutText message.

+

Server crash when scaling factor is set to zero.

+

Multiple stack overflows in File Transfer feature.

+
+ +
+ + http://seclists.org/oss-sec/2014/q3/639 + CVE-2014-6051 + CVE-2014-6052 + CVE-2014-6053 + CVE-2014-6054 + CVE-2014-6055 + + + 2014-09-23 + 2016-10-07 + +
+ BIND -- Remote Denial of Service vulnerability