Re: various security issues in VNC related packages

2019-11-04 Thread Mike Gabriel
Hi Ola, On Mo 04 Nov 2019 09:58:27 CET, Ola Lundqvist wrote: Hi Mike Please go ahead. I will be off for some time due to a planned surgery so it would be very good if you can fix this. // Ola ACK. Good luck with the surgery. Mike -- DAS-NETZWERKTEAM c\o Technik- und Ökologiezentrum Ecke

Re: various security issues in VNC related packages

2019-11-04 Thread Ola Lundqvist
Hi Mike Please go ahead. I will be off for some time due to a planned surgery so it would be very good if you can fix this. // Ola On Thu, 31 Oct 2019 at 08:55, Mike Gabriel wrote: > Hi Ola, > > On Mi 30 Okt 2019 21:20:50 CET, Ola Lundqvist wrote: > > > Hi > > > > I agree that the VNC situati

Re: various security issues in VNC related packages

2019-10-31 Thread Mike Gabriel
Hi Ola, On Mi 30 Okt 2019 21:20:50 CET, Ola Lundqvist wrote: Hi I agree that the VNC situation in Debian is sub-optimal. Frankly speaking not just in Debian. This popular software has diverged quite a lot with lot of packages sharing similar code-base. I had a brief look at vnc4 as well. It

Re: various security issues in VNC related packages

2019-10-30 Thread Ola Lundqvist
Hi I agree that the VNC situation in Debian is sub-optimal. Frankly speaking not just in Debian. This popular software has diverged quite a lot with lot of packages sharing similar code-base. I had a brief look at vnc4 as well. It does not seem to share the same code base as libvncserver so it sh

various security issues in VNC related packages

2019-10-30 Thread Mike Gabriel
Hi all, today I looked into libvncserver/CVE-2019-15681. The VNC situation is non-optimal in Debian... The gist (which also applies to Debian) can be found in [1]. Thanks to Pavel Cheremushkin from Kaspersky for publishing his findings. I looked at all packages I could think of that are r