USN-3171-1: LibVNCServer vulnerabilities
Published Jan 11, 2017
·Updated
Josef Gajdusek discovered that the LibVNCServer client library incorrectly handled certain FrameBufferUpdate messages. If a user were tricked into connecting to a malicious server, an attacker could use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2016-9941, CVE-2016-9942)
Affected Software
12 affected componentsFixes available
All of the following
ubuntu/libvncclient1<0.9.10+dfsg-3ubuntu0.16.10.1
0.9.10+dfsg-3ubuntu0.16.10.1
Ubuntu Ubuntu=16.10
All of the following
ubuntu/libvncserver1<0.9.10+dfsg-3ubuntu0.16.10.1
0.9.10+dfsg-3ubuntu0.16.10.1
Ubuntu Ubuntu=16.10
All of the following
ubuntu/libvncclient1<0.9.10+dfsg-3ubuntu0.16.04.1
0.9.10+dfsg-3ubuntu0.16.04.1
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libvncserver1<0.9.10+dfsg-3ubuntu0.16.04.1
0.9.10+dfsg-3ubuntu0.16.04.1
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libvncserver0<0.9.9+dfsg-1ubuntu1.2
0.9.9+dfsg-1ubuntu1.2
Ubuntu Ubuntu=14.04
All of the following
ubuntu/libvncserver0<0.9.8.2-2ubuntu1.2
0.9.8.2-2ubuntu1.2
Ubuntu Ubuntu=12.04
Event History
Jan 11, 2017
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is CVE-2016-9941.
2
What is the severity of CVE-2016-9941?
The severity of CVE-2016-9941 is not provided in the advisory.
3
How does the vulnerability CVE-2016-9941 affect LibVNCServer?
The vulnerability CVE-2016-9941 affects the LibVNCServer client library.
4
How can an attacker exploit CVE-2016-9941?
An attacker can exploit CVE-2016-9941 by tricking a user into connecting to a malicious server.
5
Is there a fix available for CVE-2016-9941?
Yes, a fix is available for CVE-2016-9941. Users should update to version 0.9.10+dfsg-3ubuntu0.16.10.1 of libvncclient1 and libvncserver1.