Your message dated Sun, 19 Apr 2026 18:32:43 +0000
with message-id <[email protected]>
and subject line Bug#1132017: fixed in libvncserver 0.9.15+dfsg-1+deb13u1
has caused the Debian Bug report #1132017,
regarding libvncserver: CVE-2026-32854
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1132017: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1132017
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libvncserver
Version: 0.9.15+dfsg-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for libvncserver.
CVE-2026-32854[0]:
| LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee)
| contain null pointer dereference vulnerabilities in the HTTP proxy
| handlers within httpProcessInput() in httpd.c that allow remote
| attackers to cause a denial of service by sending specially crafted
| HTTP requests. Attackers can exploit missing validation of strchr()
| return values in the CONNECT and GET proxy handling paths to trigger
| null pointer dereferences and crash the server when httpd and proxy
| features are enabled.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-32854
https://www.cve.org/CVERecord?id=CVE-2026-32854
[1]
https://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x
[2]
https://github.com/LibVNC/libvncserver/commit/dc78dee51a7e270e537a541a17befdf2073f5314
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: libvncserver
Source-Version: 0.9.15+dfsg-1+deb13u1
Done: Sven Geuer <[email protected]>
We believe that the bug you reported is fixed in the latest version of
libvncserver, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Sven Geuer <[email protected]> (supplier of updated libvncserver package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 06 Apr 2026 22:55:25 +0200
Source: libvncserver
Architecture: source
Version: 0.9.15+dfsg-1+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Debian Remote Maintainers <[email protected]>
Changed-By: Sven Geuer <[email protected]>
Closes: 1132016 1132017
Changes:
libvncserver (0.9.15+dfsg-1+deb13u1) trixie; urgency=medium
.
* Team upload.
* debian/patches:
+ CVE-2026-32853: Add 0001_CVE-2026-32853.patch fixing a heap out-of-bounds
read (Closes: #1132016).
+ CVE-2026-32854: Add 0002_CVE-2026-32854.patch fixing NULL pointer
dereferences in httpd proxy handlers (Closes: #1132017).
Checksums-Sha1:
dccb764fd1a887c367d2050bcc0709cdfbdd3d7a 2345
libvncserver_0.9.15+dfsg-1+deb13u1.dsc
753c14b8c1af0d3dbf8e5424e6fb66d5dc075fea 19468
libvncserver_0.9.15+dfsg-1+deb13u1.debian.tar.xz
f6daded08e986bf3fdca9337c50154b4ca116afe 8721
libvncserver_0.9.15+dfsg-1+deb13u1_amd64.buildinfo
Checksums-Sha256:
a9d0399b04d1a44c86c7c5236ad18685cf1fbc9e7546ad9f48199366f17bbd73 2345
libvncserver_0.9.15+dfsg-1+deb13u1.dsc
510285c36d733a1b8e5e5438354b01e528795d948f893b73c2d51b5d47de0c41 19468
libvncserver_0.9.15+dfsg-1+deb13u1.debian.tar.xz
560aa4a64f4e3b55231919a1f192a4efc2e3c4c7d1792a0ca9449767638b74cd 8721
libvncserver_0.9.15+dfsg-1+deb13u1_amd64.buildinfo
Files:
db859c41093337477ffc3fa97b9fe076 2345 libs optional
libvncserver_0.9.15+dfsg-1+deb13u1.dsc
a2da7080bdc38263ed8a9037b533823d 19468 libs optional
libvncserver_0.9.15+dfsg-1+deb13u1.debian.tar.xz
4b0d70cf9c2c64a60244e384a13ebbe7 8721 libs optional
libvncserver_0.9.15+dfsg-1+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJDBAEBCgAtFiEEPfXoqkP8n9/QhvGVrfUO2vit1YUFAmnUHlkPHHNnZUBkZWJp
YW4ub3JnAAoJEK31Dtr4rdWF820QAMtciPe5QNxle1pKCWfXZHRTvYkLPqnvyirP
amzM2a9nZ+6WwnPxR2/iQ3sZl+x37boTlMaBNUVUcnlRMIbee3N9xxalYZFCJ8nj
M37xIgJTk3U81eCOXPifhV2AyM9413Ddx9QSqoiOEqAJrYpBmT7trwFrO2EoDDML
IydcFckz4loLWtTnMaNxJRTp9laRKG/mXJ7WapQUdI6rJF8vSdTTeedb02fmvENm
f8SZp9EVvzSs2NMZxwi9iAW+DYuFNE/uqPETpb313hgS5KR+SIAfl7enPja+oe5e
YOrSQ8nYXDnCtPDjb/2uaxHqtmKtwHK0qumqvd5/UF2+MhDMikXq3OBMyqQcG7ny
I2Os0akkcf1tOrRZv2U9eZ8KmVBiXJ1XJlme9Nnb6Eygf06b2JkpRPWg5u6wpBLG
6KLYht48aCbtsOOeqBx4esyZtvWegyBzzG1oSwXsKt4iOZzF4YQ5DEJYjREO13N7
uPWrwN4z63pDsyWNmvbRgkp/pAe9hICUE+3vvNxXo1i3jYmHD5DCpt940FvOVWcx
QU11rAV9I0QThMJp1xrzwo1HL/QuL4m2HZ7xU5+uFLpvBVjCItvKJfRv3kYCGUpw
hDBIRZfh5fHAqsBr7HED/6aR2ENyYBN1o9oqGxIc5sZeua3ZKHpV33fiMNogAkY3
QriGfmU5
=UFEs
-----END PGP SIGNATURE-----
pgp2_e42PG3OT.pgp
Description: PGP signature
--- End Message ---