{"id":"MGASA-2015-0459","summary":"Updated tigervnc packages fix security vulnerabilities","details":"Updated tigervnc packages fix security vulnerabilities:\n\nAn integer overflow flaw, leading to a heap-based buffer overflow, was\nfound in the way TigerVNC handled screen sizes. A malicious VNC server\ncould use this flaw to cause a client to crash or, potentially, execute\narbitrary code on the client (CVE-2014-8240).\n\nA NULL pointer dereference flaw was found in TigerVNC's XRegion.\nA malicious VNC server could use this flaw to cause a client to crash\n(CVE-2014-8241).\n","modified":"2026-04-16T06:26:24.935015911Z","published":"2015-11-26T20:47:39Z","upstream":["CVE-2014-8240","CVE-2014-8241"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0459.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=17190"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2015-2233.html"}],"affected":[{"package":{"name":"tigervnc","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/tigervnc?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.1-6.1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0459.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}