{"id":"MGASA-2021-0040","summary":"Updated synergy packages fix a security vulnerability","details":"In Synergy before version 1.12.0, a Synergy server can be crashed by receiving\na kMsgHelloBack packet with a client name length set to 0xffffffff (4294967295)\nif the servers memory is less than 4 GB. It was verified that this issue does\nnot cause a crash through the exception handler if the available memory of the\nServer is more than 4GB (CVE-2020-15117).\n\nThe synergy package has been updated to version 1.12.0, fixing this issue and\nseveral other bugs.\n","modified":"2026-04-16T04:44:08.658747955Z","published":"2021-01-17T16:07:01Z","upstream":["CVE-2020-15117"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0040.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=27851"},{"type":"ADVISORY","url":"https://github.com/symless/synergy-core/security/advisories/GHSA-chfm-333q-gfpp"},{"type":"WEB","url":"https://github.com/symless/synergy-core/releases/tag/1.11.0-stable"},{"type":"WEB","url":"https://github.com/symless/synergy-core/releases/tag/v1.11.1-stable"},{"type":"WEB","url":"https://github.com/symless/synergy-core/releases/tag/v1.12.0-stable"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/VFDEQED64YLWQK2TF73EMXZDYX7YT2DD/"}],"affected":[{"package":{"name":"synergy","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/synergy?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12.0-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0040.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}