| Summary: | x11vnc new security issue CVE-2020-29074 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | mageia, nicolas.salguero, ouaurelien, sysadmin-bugs |
| Version: | 7 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA7-64-OK | ||
| Source RPM: | x11vnc-0.9.16-1.mga7.src.rpm | CVE: | CVE-2020-29074 |
| Status comment: | |||
|
Description
David Walser
2020-11-29 16:57:34 CET
David Walser
2020-11-29 16:57:41 CET
Whiteboard:
(none) =>
MGA7TOO In the absence of any consistent maintainer for x11vnc, must assign this globally. Assignee:
bugsquad =>
pkg-bugs Suggested advisory: ======================== The updated package fixes a security vulnerability: scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user. (CVE-2020-29074) References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29074 https://www.debian.org/security/2020/dsa-4799 ======================== Updated package in core/updates_testing: ======================== x11vnc-0.9.16-1.1.mga7 from SRPM: x11vnc-0.9.16-1.1.mga7.src.rpm Assignee:
pkg-bugs =>
qa-bugs Installed and tested without issue. Tested with vncviewer, krdc and novnc_server clients. System: Mageia 7, x86_64, Plasma DE, LXQt DE, Intel CPU, nVidia GPU using nvidia-current proprietary driver. $ uname -a Linux marte 5.7.19-desktop-3.mga7 #1 SMP Sun Oct 18 15:46:00 UTC 2020 x86_64 x86_64 x86_64 GNU/Linux $ rpm -q x11vnc x11vnc-0.9.16-1.1.mga7 $ x11vnc -display :0 <SNIP> The VNC desktop is: marte:0 PORT=5900 <SNIP> $ vncviewer localhost:0 <SNIP> CConn: Conectado ao host marte porta 5900 <SNIP> CC:
(none) =>
mageia This update has been in use for almost a week without issues so I'm OKing this for x86_64 (see comment 3). Please unOK if you think its appropriate. Whiteboard:
(none) =>
MGA7-64-OK Validating. Advisory pushed to SVN. Keywords:
(none) =>
advisory, validated_update An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2020-0454.html Status:
ASSIGNED =>
RESOLVED |