[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2008:240 -- Mandriva vinagre

ID: oval:org.secpod.oval:def:301314Date: (C)2012-01-07   (M)2021-06-02
Class: PATCHFamily: unix




Alfredo Ortega found a flaw in how Vinagre uses format strings. A remote attacker could exploit this vulnerability if they were able to trick a user into connecting to a malicious VNC server, or opening a specially crafted URI with Vinagre. With older versions of Vinagre, it was possible to execute arbitrary code with user privileges. In later versions, Vinagre would abort, leading to a denial of service. The updated packages have been patched to prevent this issue.

Platform:
Mandriva Linux 2009.0
Mandriva Linux 2008.1
Product:
vinagre
Reference:
MDVSA-2008:240
CPE    2
cpe:/o:mandriva:linux:2008.1
cpe:/o:mandriva:linux:2009.0

© SecPod Technologies