[ GLSA 202006-06 ] ssvnc: Multiple vulnerabilities

Aaron Bauman <[email protected]>
Newsgroups gmane.linux.gentoo.announce
Message-ID <20200613011009.GD17996@bubba>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202006-06
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Normal
    Title: ssvnc: Multiple vulnerabilities
     Date: June 13, 2020
     Bugs: #701820
       ID: 202006-06

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in ssvnc, the worst of which
could result in the arbitrary execution of code.

Background
==========

The Enhanced TightVNC Viewer, SSVNC, adds encryption security to VNC
connections.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  net-misc/ssvnc             <= 1.0.29-r2               Vulnerable!
    -------------------------------------------------------------------
     NOTE: Certain packages are still vulnerable. Users should migrate
           to another package if one is available or wait for the
           existing packages to be marked stable by their
           architecture maintainers.

Description
===========

Multiple vulnerabilities have been discovered in ssvnc. Please review
the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

Gentoo has discontinued support for ssvnc. We recommend that users
unmerge ssvnc:

  # emerge --unmerge "net-misc/ssvnc"

NOTE: The Gentoo developer(s) maintaining ssvnc have discontinued
support at this time. It may be possible that a new Gentoo developer
will update ssvnc at a later date. An alternative may be a manual SSH
tunnel.

References
==========

[ 1 ] CVE-2018-20020
      https://nvd.nist.gov/vuln/detail/CVE-2018-20020
[ 2 ] CVE-2018-20021
      https://nvd.nist.gov/vuln/detail/CVE-2018-20021
[ 3 ] CVE-2018-20022
      https://nvd.nist.gov/vuln/detail/CVE-2018-20022
[ 4 ] CVE-2018-20024
      https://nvd.nist.gov/vuln/detail/CVE-2018-20024

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202006-06

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2020 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE-----

iQEzBAABCAAdFiEEDA48qNrrn8VVVcst4yp5f7HQy3AFAl7kJ3EACgkQ4yp5f7HQ
y3ATaAf9GHoSp6Xl45FFWHO2CyZrkfISMVlFfxjUCVNO3mURdcx76Kkn1intlBIu
sfIZP38Sf037dMYf/W85RbNX2O555+1ENE8yeYDFf4v0Roqwkojz8TWUkDnv825s
igZSQcpX3c2TzOZnzE3vchylvgG+o52Tt/0RHgbdg7uawGVBmehAHw3eK5bAV/cJ
ND+qEE2P7N9sQJ/ZK2NUkdqaVlJLBX3wQX+cw/xZNSZ8vQjTFxr+zLyYP6muKhcz
NhLmMgVGrniu8+sq17KasmHzniFGYrWthOmtCnvV3Pl29ph2t7swbo18xpQnGlqL
UnjkT29ADjwDHZROhkXNPfF4NWUD0g==
=Krao
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.