USN-4636-1: LibVNCServer, Vino vulnerability
17 November 2020
LibVNCServer and Vino could be made to crash.
Releases
Packages
- libvncserver - vnc server library
- vino - VNC server for GNOME
Details
It was discovered that LibVNCServer incorrectly handled certain internals.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
Vino package ships with a LibVNCServer source and all listed releases were
affected for this package.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.10
Ubuntu 20.04
-
libvncclient1
-
0.9.12+dfsg-9ubuntu0.3
-
libvncserver1
-
0.9.12+dfsg-9ubuntu0.3
-
vino
-
3.22.0-5ubuntu2.2
Ubuntu 18.04
-
libvncclient1
-
0.9.11+dfsg-1ubuntu1.4
-
libvncserver1
-
0.9.11+dfsg-1ubuntu1.4
-
vino
-
3.22.0-3ubuntu1.2
Ubuntu 16.04
-
libvncclient1
-
0.9.10+dfsg-3ubuntu0.16.04.6
-
libvncserver1
-
0.9.10+dfsg-3ubuntu0.16.04.6
-
vino
-
3.8.1-0ubuntu9.4
In general, a standard system update will make all the necessary changes.