Vinagre: User-assisted execution of arbitrary code
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200903-01 / vinagre |
| Release Date |
March 06, 2009 |
| Latest Revision |
March 06, 2009: 01 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-misc/vinagre |
<
0.5.2 |
>=
0.5.2 |
All supported architectures
|
Related bugreports:
#250314
Synopsis
A format string error in Vinagre may allow for the execution of arbitrary
code.
2.
Impact Information
Background
Vinagre is a VNC Client for the GNOME Desktop.
Description
Alfredo Ortega (Core Security Technologies) reported a format string
error in the vinagre_utils_show_error() function in
src/vinagre-utils.c.
Impact
A remote attacker could entice a user into opening a specially crafted
.vnc file or connecting to a malicious server, possibly resulting in
the remote execution of arbitrary code with the privileges of the user
running the application.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Vinagre users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/vinagre-0.5.2"
|
4.
References
|