Changelog
libvncserver (0.9.11+dfsg-1.3) unstable; urgency=medium
* Non-maintainer upload.
* LibVNCClient: ignore server-sent cut text longer than 1MB (CVE-2018-20748)
(Closes: #920941)
* LibVNCClient: ignore server-sent reason strings longer than 1MB
(CVE-2018-20748) (Closes: #920941)
* LibVNCClient: fail on server-sent desktop name lengths longer than 1MB
(CVE-2018-20748) (Closes: #920941)
* LibVNCClient: remove now-useless cast (CVE-2018-20748) (Closes: #920941)
* Error out in rfbProcessFileTransferReadBuffer if length can not be
allocated (CVE-2018-20749) (Closes: #920941)
* Limit lenght to INT_MAX bytes in rfbProcessFileTransferReadBuffer()
(CVE-2018-20750) (Closes: #920941)
-- Salvatore Bonaccorso <email address hidden> Wed, 30 Jan 2019 22:39:15 +0100