| Commit message (Collapse) | Author | Age | Files | Lines |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
This patch constrains a client cut text length to 1 MB. Otherwise
a client could make server allocate 2 GB of memory and that seems to
be to much to classify it as a denial of service.
The limit also prevents from an integer overflow followed by copying
an uninitilized memory when processing msg.cct.length value larger
than SIZE_MAX or INT_MAX - sz_rfbClientCutTextMsg.
This patch also corrects accepting length value of zero (malloc(0) is
interpreted on differnet systems differently).
CVE-2018-7225
<https://github.com/LibVNC/libvncserver/issues/218>
(cherry picked from commit 28afb6c537dc82ba04d5f245b15ca7205c6dbb9c)
|
|
|
|
| |
Signed-off-by: Michele Calgaro <michele.calgaro@yahoo.it>
|
|
|
|
| |
Signed-off-by: Michele Calgaro <michele.calgaro@yahoo.it>
|
| |
|
| |
|
|
|
|
|
|
|
| |
This resolves FTBFS on FreeBSD 12.
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit 95285a6e5630a0a02a2cc6fe9feb49e71038bed7)
|
|
|
|
| |
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
|
|
|
|
|
|
|
|
|
| |
OS X RealVNC server crashes out Remmina because the server can provoke
bytesPerLine to be zero. Assume this is coding for zero lines.
The condition could be checked before the calculation of bytesPerLine.
I don’t understand the preconditions of this code to say one way or the
other.
|
|
|
|
|
| |
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit 9f6b1118bc6eff9f22f719620753175fa4dc09f5)
|
| |
|
| |
|
|
|
|
|
| |
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit dca06b0505ba4de236055aac0d5cf635fdc85709)
|
| |
|
| |
|
|
|
|
|
| |
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit ba6db0daa96b932cb8a5cfe83ae1449c90c1b7f1)
|
|
|
|
|
| |
Signed-off-by: Fabio Rossi <rossi.f@inwind.it>
(cherry picked from commit 66285bb35a79aba7b02651d7ec4d9c753e0828cc)
|
| |
|
| |
|
| |
|
| |
|
| |
|
|
|
|
|
|
| |
Signed-off-by: gregory guy <g-gregory@gmx.fr>
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit 2a97cbef310033828c3823382ea9e0dfbcb46ca1)
|
|
|
|
|
| |
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit 94033dc8bbdc719864d178f67d9a32396ec35583)
|
| |
|
|
|
|
|
| |
Signed-off-by: Michele Calgaro <michele.calgaro@yahoo.it>
(cherry picked from commit e524e3be92f1a7c10fd8dba6e53d52b7b2666054)
|
|
|
|
|
| |
Signed-off-by: Michele Calgaro <michele.calgaro@yahoo.it>
(cherry picked from commit 28ea76eab7dbb4fb641217650c4cbe8c023cbc2e)
|
|
|
|
|
| |
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit c0dd6fa720aa2e5c9a7bbc7f169ec7912905bd3a)
|
| |
|
|
|
|
|
| |
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit 3fcbeef084f778509b1ae3753c375295f61cd1f3)
|
|
|
|
|
|
|
| |
This relates to bug 2669
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit 449164733b0a1a3096ca1bbd33efee178b95bd82)
|
| |
|
| |
|
| |
|
|
|
|
|
| |
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit 036b0229dba794cf6267b522ac1f6449b6708d51)
|
|
|
|
|
|
|
|
| |
AIM network has been shutdown in 2017-12-15
This resolves Bug 2846
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit dc34f9c39105b0fe20ba45c064a08406084acbe2)
|
|
|
|
|
| |
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit f6fd4ab6c01a9deb7a1eabb7f8aa908676831eba)
|
|
|
|
|
| |
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit c49165ddb7b3a260298e606fc4d4e9fb3b290bca)
|
|
|
|
|
|
|
| |
MSN protocol has already been dropped in commit 04860347
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit 2d5f9c55daa532c5f19e6defebc7767c6d04c556)
|
| |
|
| |
|
|
|
|
|
| |
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit ed71acf6dcd9380590048fc5c6eb9fd22cb3b9c5)
|
| |
|
| |
|
| |
|
| |
|
|
|
|
|
|
|
| |
This resolves FTBFS on FreeBSD
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit 46042bc67e2ab5df2f486bf78b78b421fc67b59c)
|
|
|
|
|
| |
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit 182234c826322c90bed4e02bd0846372b83c245f)
|
|
|
|
|
| |
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit a2f55c2d170e5c9ccd00e4bd42e05b689b7e402e)
|
|
|
|
|
| |
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit 9faa91eecd162a3d9758a2ecd951578e9b7b19e6)
|
|
|
|
|
|
|
| |
This resolves bug 2723
Signed-off-by: Slávek Banko <slavek.banko@axis.cz>
(cherry picked from commit 244c1e03a0954ef3f3cb9716f9c90ac2fb26bf39)
|