🕵️ SicherheitslückenSQLi & XSS Vulnerabilities in a Popular Airlines Website!(10.10.2017 um 20:34 Uhr)
🕵️ SicherheitslückenBugcrowd’s Domain & Subdomain Takeover vulnerability!(10.10.2017 um 21:20 Uhr)
🕵️ SicherheitslückenUnrestricted File Upload to RCE | Bug Bounty POC(19.12.2017 um 13:48 Uhr)
🕵️ SicherheitslückenHow I was able to Bypass XSS Protection on HackerOne's Private Program(02.02.2018 um 13:10 Uhr)
🕵️ SicherheitslückenIOS 11.4 Siri Auth Bypass | CVE-2018-4238(22.05.2018 um 15:31 Uhr)
🪟 Windows TippsHow to Enable Windows 11 Screen Savers(07.09.2026 um 12:41 Uhr)
🪟 Windows TippsMicrosoft Phone Link Not Showing Messages on Windows 11? Fix It(09.09.2026 um 07:52 Uhr)
🕵️ SicherheitslückenSQLi & XSS Vulnerabilities in a Popular Airlines Website!(10.10.2017 um 20:34 Uhr)
🕵️ SicherheitslückenBugcrowd’s Domain & Subdomain Takeover vulnerability!(10.10.2017 um 21:20 Uhr)
🕵️ SicherheitslückenUnrestricted File Upload to RCE | Bug Bounty POC(19.12.2017 um 13:48 Uhr)
🕵️ SicherheitslückenHow I was able to Bypass XSS Protection on HackerOne's Private Program(02.02.2018 um 13:10 Uhr)
🕵️ SicherheitslückenIOS 11.4 Siri Auth Bypass | CVE-2018-4238(22.05.2018 um 15:31 Uhr)
🪟 Windows TippsHow to Enable Windows 11 Screen Savers(07.09.2026 um 12:41 Uhr)
🪟 Windows TippsMicrosoft Phone Link Not Showing Messages on Windows 11? Fix It(09.09.2026 um 07:52 Uhr)
1 Tag Serie
🐧 Unix Server 🕛 vor 9 Jahren 1 Min Lesezeit CVE-2016-9941
0

USN-3171-1: LibVNCServer vulnerabilities

Cyber Threat & Vulnerability Dossier CVSS 5.8 MEDIUM (Heuristik) EPSS 5.1%
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
⛔ Dienstausfall (DoS) / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
Im CVE-Radar öffnen
↗ Quelle (ubuntu.com)
🗣️ Stimme:
📑 Inhaltsübersicht

Ubuntu Security Notice USN-3171-1


11th January, 2017


libvncserver vulnerabilities


A security issue affects these releases of Ubuntu and its
derivatives:


  • Ubuntu 16.10


  • Ubuntu 16.04 LTS


  • Ubuntu 14.04 LTS


  • Ubuntu 12.04 LTS


Summary


Several security issues were fixed in LibVNCServer.





Software description


  • libvncserver
    - vnc server library










Details


Josef Gajdusek discovered that the LibVNCServer client library incorrectly
handled certain FrameBufferUpdate messages. If a user were tricked into
connecting to a malicious server, an attacker could use this issue to cause
a denial of service, or possibly execute arbitrary code. ()



Update instructions


The problem can be corrected by updating your system to the following
package version:


Ubuntu 16.10:

















Ubuntu 16.04 LTS:

















Ubuntu 14.04 LTS:










Ubuntu 12.04 LTS:










To update your system, please follow these instructions:
,

CVE-2016-9942


Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf ubuntu.com.
↗ Original-Artikel auf ubuntu.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
Bugcrowd’s Domain & Subdomain Takeover vulnerability!
1 Quelle
SQLi & XSS Vulnerabilities in a Popular Airlines Website!
1 Quelle
Unrestricted File Upload to RCE | Bug Bounty POC