Package: libvncserver0
Version: 0.9.9+dfsg-4
Severity: important
Tags: upstream patch ipv6

Dear Maintainer,


I was encountering x11vnc crashes when connecting in, due to "buffer
overflow detected" errors. I believe this is the same bug #735648
reported as "x11vnc: buffer overflow detected: x11vnc terminated"
(just in case link to not generated,
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=735648).

I have tracked this down to a bug in libvncserver/sockets.c whereby
FD_ISSET is being called against a bind socket fd that is -1, in my
case ipv6, which I am forcing off.

I found that this was patched upstream for the post 0.9.9 release,
0.9.10, which is not yet released (judging from project activity, may
be a while coming).

The patch is here:
https://github.com/LibVNC/libvncserver/commit/66282f58000c8863e104666c30cb67b1d5cbdee3

I've compiled against it and confirmed it resolves the issue. Can you
please apply?

Thanks in advance,
Shaddy

-- System Information:
Distributor ID: Raspbian
Description:    Raspbian GNU/Linux testing (jessie)
Release:        testing
Codename:       jessie
Architecture: armv6l

Kernel: Linux 3.10.25+ (PREEMPT)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages libvncserver0 depends on:
ii  libc6              2.18-4
ii  libgcrypt11        1.5.3-4
ii  libgnutls26        2.12.23-13
ii  libjpeg8           8d-2
ii  multiarch-support  2.18-4
ii  zlib1g             1:1.2.8.dfsg-1

libvncserver0 recommends no packages.

libvncserver0 suggests no packages.

-- no debconf information


--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to