You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa tigervnc

Sigurnosni nedostatak programskog paketa tigervnc

Fedora Update Notification
2014-03-21 07:16:38

Name : tigervnc
Product : Fedora 20
Version : 1.3.0
Release : 14.fc20
Summary : A TigerVNC remote display system
Description :
Virtual Network Computing (VNC) is a remote display system which
allows you to view a computing ‘desktop’ environment not only on the
machine where it is running, but from anywhere on the Internet and
from a wide variety of machine architectures. This package contains a
client which will allow you to connect to other desktops running a VNC

Update Information:

This update fixes CVE-2014-0011, a ZRLE decoding heap-based buffer overflow in vncviewer.

* Wed Mar 19 2014 Tim Waugh <> 1.3.0-14
– Fixed heap-based buffer overflow (CVE-2014-0011, bug #1050928).
* Mon Feb 10 2014 Tim Waugh <> 1.3.0-13
– Clearer xstartup file (bug #923655).
* Tue Jan 14 2014 Tim Waugh <> 1.3.0-12
– Fixed instructions in systemd unit file.
* Fri Jan 10 2014 Tim Waugh <> 1.3.0-11
– Fixed viewer crash when cursor has not been set (bug #1038701).
* Thu Dec 12 2013 Tim Waugh <> 1.3.0-10
– Avoid invalid read when ZRLE connection closed (upstream bug #133).
* Tue Dec 3 2013 Tim Waugh <> 1.3.0-9
– Fixed build failure with -Werror=format-security (bug #1037358).
* Thu Nov 7 2013 Adam Jackson <> 1.3.0-8
– Rebuild against xserver 1.15RC1

[ 1 ] Bug #1050928 – CVE-2014-0011 tigervnc: ZRLE decoding heap-based buffer overflow in vncviewer

This update can be installed with the “yum” update program. Use
su -c ‘yum update tigervnc’ at the command line.
For more information, refer to “Managing Software with yum”,
available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list

More in Preporuke
Sigurnosni nedostaci programskog paketa chromium-browser

Otkriveni su sigurnosni nedostaci u programskom paketu chromium-browser. Otkriveni nedostaci potencijalnim napadačima omogućuju izvođenje napada uskraćivanjem usluge, uvid u osjetljive...
