Re: various security issues in VNC related packages

2019-10-30 Thread Ola Lundqvist
Hi I agree that the VNC situation in Debian is sub-optimal. Frankly speaking not just in Debian. This popular software has diverged quite a lot with lot of packages sharing similar code-base. I had a brief look at vnc4 as well. It does not seem to share the same code base as libvncserver so it sh

various security issues in VNC related packages

2019-10-30 Thread Mike Gabriel
Hi all, today I looked into libvncserver/CVE-2019-15681. The VNC situation is non-optimal in Debian... The gist (which also applies to Debian) can be found in [1]. Thanks to Pavel Cheremushkin from Kaspersky for publishing his findings. I looked at all packages I could think of that are r