-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4755-1                [email protected]
https://www.debian.org/lts/security/                          Abhijith PA
August 25, 2026                               https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : libvncserver
Version        : 0.9.13+dfsg-2+deb11u2
CVE ID         : CVE-2026-32853 CVE-2026-32854 CVE-2026-44988 CVE-2026-50538
Debian Bug     : 1132016 1132017 1138174 1138253

Several vulnerabilities were discovered in libvncserver, a
cross-platform library to implement VNC server or client functionality
in program

CVE-2026-32853

    a heap out-of-bounds read vulnerability in the UltraZip encoding
    handler that allows a malicious VNC server to cause information
    disclosure or application crash. Attackers can exploit improper
    bounds checking in the HandleUltraZipBPP() function by
    manipulating subrectangle header counts to read beyond the
    allocated heap buffer

CVE-2026-32854

    null pointer dereference vulnerabilities in the HTTP proxy
    handlers within httpProcessInput() in httpd.c that allow remote
    attackers to cause a denial of service by sending specially
    crafted HTTP requests. Attackers can exploit missing validation of
    strchr() return values in the CONNECT and GET proxy handling paths
    to trigger null pointer dereferences and crash the server when
    httpd and proxy features are enabled.

CVE-2026-44988

    LibVNCClient Tight Gradient decoding allows malicious
    server-triggered heap/stack out-of-bounds writes

CVE-2026-50538

    a malicious (or man-in-the-middle) VNC server can force a
    connecting `libvncclient` to write attacker-controlled data past
    the end of its framebuffer. This is an out-of-bounds heap write
    with attacker-controlled length, contents, and offset.

For Debian 11 bullseye, these problems have been fixed in version
0.9.13+dfsg-2+deb11u2.

We recommend that you upgrade your libvncserver packages.

For the detailed security status of libvncserver please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libvncserver

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmqNmSsACgkQhj1N8u2c
KO9W0g//YKA73MJlhROV24z+MrrtQ8B3rABWKviPak8c0mUy2nzWdvHAVcyFuv8o
GOo3FxPXpJC44e9zE31qPzlLPm4FjyHuFUK+eb7nXCEBVgTnHf+nC3glNFyhpaLn
gayvxrnUrOxvcO00z0cdObPEHsrxUSqCSDECgem5MER9MSr1gOaCFl2mcqFJ1rMq
xSS2Nx0f3DpKJSMy+K8Jgipakd3LlrMOaXAdFssdW2FxPrvi4QD1XeeuXZ8mxlrj
i3ZVNpa8mP3iySBN2Y5OYcDCK2pGk4mJisakm7Yxbbe0LTB/MRAtHatw+A0Lzy/G
AkK98ybnOqoK2G7DKDNOI/DqtOCDR4QwJSzzVrVkJc8SXzrd+Sc10p8AvuCePXjq
Elo0EUhyd/N7EcnDkrKppQGk2+5I73pgzl5u1p+5lQ5MPd8SCZEb2xC1tSzK1x6b
q6BUA/W6epqi8hXprNfxDR3+wfXsWrXzJYmHlpjsC6xOr33SscNkgfq8CS3RRi6y
WTFDNrO9WNl58ecBPBw5Ob998j6g7VLtqB/ZX6QExmT2QcEo5vgN5Fjln/tuQr4t
EE7AVzWfbr8B+b7HDMWMKNuaK+5Dc8gAbJWEtLS0X5JQBKAZKjAOtNSe9nvQ6429
VI9+vykaEwuNvx+vfqb1AHPZQAa+G2Bc8zsrrEDZMJi0XFx43ps=
=RVVR
-----END PGP SIGNATURE-----

Reply via email to