various security issues in VNC related packages

2019-10-30 Thread Mike Gabriel
Hi all, today I looked into libvncserver/CVE-2019-15681. The VNC situation is non-optimal in Debian... The gist (which also applies to Debian) can be found in [1]. Thanks to Pavel Cheremushkin from Kaspersky for publishing his findings. I looked at all packages I could think of that are r

Re: various security issues in VNC related packages

2019-10-30 Thread Ola Lundqvist
Hi I agree that the VNC situation in Debian is sub-optimal. Frankly speaking not just in Debian. This popular software has diverged quite a lot with lot of packages sharing similar code-base. I had a brief look at vnc4 as well. It does not seem to share the same code base as libvncserver so it sh

Upcoming stable point release (10.2)

2019-10-30 Thread Adam D. Barratt
Hi, The next point release for "buster" (10.2) is scheduled for Saturday, November 16th. Processing of new uploads into buster-proposed-updates will be frozen during the preceding weekend. Regards, Adam