PT-2014-1820 · Kde+6 · Kdenetwork-Devel+19

Nicolas Ruff

·

Published

2014-09-24

·

Updated

2020-10-23

·

CVE-2014-6054

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions kdenetwork-kopete-devel version 4.10.5 kdenetwork-krdc version 4.10.5 kdenetwork-kopete version 4.10.5 kdenetwork-kget-libs version 4.10.5 kdenetwork-krfb-libs version 4.10.5 kdenetwork-kdnssd version 4.10.5 kdenetwork-common version 4.10.5 kdenetwork-fileshare-samba version 4.10.5 kdenetwork-devel version 4.10.5 kdenetwork-kget version 4.10.5 kdenetwork-krdc-libs version 4.10.5 kdenetwork-krdc-devel version 4.10.5 kdenetwork-krfb version 4.10.5 kdenetwork-debuginfo version 4.10.5 LibVNCServer version 0.9.9 and earlier
Description The issue is related to multiple vulnerabilities in various packages of the kdenetwork suite, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely by an attacker who has passed the authentication procedure. Additionally, a vulnerability in the LibVNCServer library can cause a denial of service (divide-by-zero error and server crash) via a zero value in the scaling factor in a PalmVNCSetScaleFactor or SetScale message.
Recommendations For kdenetwork-kopete-devel version 4.10.5, restrict access to the vulnerable components to minimize the risk of exploitation. For kdenetwork-krdc version 4.10.5, consider disabling the remote access functionality until a patch is available. For kdenetwork-kopete version 4.10.5, avoid using the vulnerable features until the issue is resolved. For kdenetwork-kget-libs version 4.10.5, restrict access to the vulnerable libraries to minimize the risk of exploitation. For kdenetwork-krfb-libs version 4.10.5, consider disabling the vulnerable libraries until a patch is available. For kdenetwork-kdnssd version 4.10.5, restrict access to the vulnerable components to minimize the risk of exploitation. For kdenetwork-common version 4.10.5, avoid using the vulnerable features until the issue is resolved. For kdenetwork-fileshare-samba version 4.10.5, restrict access to the vulnerable components to minimize the risk of exploitation. For kdenetwork-devel version 4.10.5, consider disabling the vulnerable development tools until a patch is available. For kdenetwork-kget version 4.10.5, restrict access to the vulnerable components to minimize the risk of exploitation. For kdenetwork-krdc-libs version 4.10.5, avoid using the vulnerable libraries until the issue is resolved. For kdenetwork-krdc-devel version 4.10.5, consider disabling the vulnerable development tools until a patch is available. For kdenetwork-krfb version 4.10.5, restrict access to the vulnerable components to minimize the risk of exploitation. For kdenetwork-debuginfo version 4.10.5, avoid using the vulnerable debugging tools until the issue is resolved. For LibVNCServer version 0.9.9 and earlier, update to a newer version to mitigate the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1418
BDU:2015-06221
BDU:2015-06222
BDU:2015-06223
BDU:2015-06224
BDU:2015-06225
BDU:2015-06226
BDU:2015-06227
BDU:2015-06228
BDU:2015-06229
BDU:2015-06230
BDU:2015-06231
BDU:2015-06232
BDU:2015-06233
BDU:2015-06234
BDU:2015-06235
BDU:2015-06236
BDU:2015-09227
BDU:2015-09228
BDU:2015-09229
BDU:2015-09230
BDU:2015-09231
BDU:2015-09232
BDU:2015-09233
BDU:2015-09234
BDU:2015-09235
BDU:2015-09236
BDU:2015-09237
BDU:2015-09238
BDU:2015-09239
BDU:2015-09240
BDU:2015-09241
BDU:2015-09242
CESA-2014_1826
CESA-2014_1827
CVE-2014-6054
DLA-197-1
DLA-1979-1
DSA-3081-1
MGASA-2014-0397
MGASA-2014-0432
MGASA-2014-0466
RHSA-2014:1826
RHSA-2014:1827
RHSA-2014_1826
RHSA-2014_1827
SUSE-SU-2015:2088-1
SUSE-SU-2015:2088-2
SUSE-SU-2015:2110-1
USN-2365-1
USN-4587-1

Affected Products

Alt Linux
Centos
Libvncserver
Red Hat
Suse
Ubuntu
Kdenetwork-Common
Kdenetwork-Debuginfo
Kdenetwork-Devel
Kdenetwork-Fileshare-Samba
Kdenetwork-Kdnssd
Kdenetwork-Kget
Kdenetwork-Kget-Libs
Kdenetwork-Kopete
Kdenetwork-Kopete-Devel
Kdenetwork-Krdc
Kdenetwork-Krdc-Devel
Kdenetwork-Krdc-Libs
Kdenetwork-Krfb
Kdenetwork-Krfb-Libs