PT-2014-1819 · Kde+7 · Kdenetwork-Kget-Libs+22

Nicolas Ruff

·

Published

2014-09-24

·

Updated

2020-10-23

·

CVE-2014-6053

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions kdenetwork-kopete-devel version 4.10.5 kdenetwork-kopete version 4.10.5 kdenetwork-krdc version 4.10.5 kdenetwork-kget-libs version 4.10.5 kdenetwork-krfb-libs version 4.10.5 kdenetwork-kdnssd version 4.10.5 kdenetwork-fileshare-samba version 4.10.5 kdenetwork-devel version 4.10.5 kdenetwork-common version 4.10.5 kdenetwork-krdc-devel version 4.10.5 kdenetwork-kget version 4.10.5 kdenetwork-krdc-libs version 4.10.5 kdenetwork-kopete-libs version 4.10.5 kdenetwork-krfb version 4.10.5 kdenetwork-debuginfo version 4.10.5
Description The issue is related to multiple vulnerabilities in the kdenetwork package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely by an attacker who has passed the authentication procedure. The vulnerabilities are associated with various components of the kdenetwork package, including kdenetwork-kopete-devel, kdenetwork-kopete, kdenetwork-krdc, kdenetwork-kget-libs, kdenetwork-krfb-libs, kdenetwork-kdnssd, kdenetwork-fileshare-samba, kdenetwork-devel, kdenetwork-common, kdenetwork-krdc-devel, kdenetwork-kget, kdenetwork-krdc-libs, kdenetwork-kopete-libs, kdenetwork-krfb, and kdenetwork-debuginfo. The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows remote attackers to cause a denial of service (memory consumption or daemon crash) via a crafted message that is processed by using a single unchecked malloc.
Recommendations For kdenetwork-kopete-devel version 4.10.5, update to a newer version to mitigate the risk. For kdenetwork-kopete version 4.10.5, update to a newer version to mitigate the risk. For kdenetwork-krdc version 4.10.5, update to a newer version to mitigate the risk. For kdenetwork-kget-libs version 4.10.5, update to a newer version to mitigate the risk. For kdenetwork-krfb-libs version 4.10.5, update to a newer version to mitigate the risk. For kdenetwork-kdnssd version 4.10.5, update to a newer version to mitigate the risk. For kdenetwork-fileshare-samba version 4.10.5, update to a newer version to mitigate the risk. For kdenetwork-devel version 4.10.5, update to a newer version to mitigate the risk. For kdenetwork-common version 4.10.5, update to a newer version to mitigate the risk. For kdenetwork-krdc-devel version 4.10.5, update to a newer version to mitigate the risk. For kdenetwork-kget version 4.10.5, update to a newer version to mitigate the risk. For kdenetwork-krdc-libs version 4.10.5, update to a newer version to mitigate the risk. For kdenetwork-kopete-libs version 4.10.5, update to a newer version to mitigate the risk. For kdenetwork-krfb version 4.10.5, update to a newer version to mitigate the risk. For kdenetwork-debuginfo version 4.10.5, update to a newer version to mitigate the risk. As a temporary workaround, consider disabling the rfbProcessClientNormalMessage function until a patch is available.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1418
BDU:2015-06221
BDU:2015-06222
BDU:2015-06223
BDU:2015-06224
BDU:2015-06225
BDU:2015-06226
BDU:2015-06227
BDU:2015-06228
BDU:2015-06229
BDU:2015-06230
BDU:2015-06231
BDU:2015-06232
BDU:2015-06233
BDU:2015-06234
BDU:2015-06235
BDU:2015-06236
BDU:2015-09227
BDU:2015-09228
BDU:2015-09229
BDU:2015-09230
BDU:2015-09231
BDU:2015-09232
BDU:2015-09233
BDU:2015-09234
BDU:2015-09235
BDU:2015-09236
BDU:2015-09237
BDU:2015-09238
BDU:2015-09239
BDU:2015-09240
BDU:2015-09241
BDU:2015-09242
CESA-2014_1826
CESA-2014_1827
CVE-2014-6053
DLA-197-1
DLA-1979-1
DLA-2014-1
DLA-2045-1
DSA-3081-1
MGASA-2014-0397
MGASA-2014-0432
MGASA-2014-0466
MGASA-2020-0242
RHSA-2014:1826
RHSA-2014:1827
RHSA-2014_1826
RHSA-2014_1827
SUSE-SU-2015:2088-1
SUSE-SU-2015:2088-2
SUSE-SU-2015:2110-1
USN-2365-1
USN-4573-1
USN-4587-1

Affected Products

Alt Linux
Astra Linux
Centos
Libvncserver
Linuxmint
Red Hat
Suse
Ubuntu
Kdenetwork-Common
Kdenetwork-Debuginfo
Kdenetwork-Devel
Kdenetwork-Fileshare-Samba
Kdenetwork-Kdnssd
Kdenetwork-Kget
Kdenetwork-Kget-Libs
Kdenetwork-Kopete
Kdenetwork-Kopete-Devel
Kdenetwork-Kopete-Libs
Kdenetwork-Krdc
Kdenetwork-Krdc-Devel
Kdenetwork-Krdc-Libs
Kdenetwork-Krfb
Kdenetwork-Krfb-Libs