italc 1:3.0.3+dfsg1-3ubuntu0.1 source package in Ubuntu

Changelog

italc (1:3.0.3+dfsg1-3ubuntu0.1) bionic-security; urgency=medium

  * SECURITY UPDATE: merge security patches from debian for heap overflows
    - debian/patches/libvncserver_CVE-2018-7225.patch: Uninitialized and
      potentially sensitive data could be accessed by remote attackers because
      the msg.cct.length in rfbserver.c was not sanitized.
    - debian/patches/libvnc_server+client_CVE-2018-15127-CVE-2018-20019.patch:
      heap out-of-bound write vulnerability.
    - debian/patches/libvncclient_CVE-2018-20020.patch: heap out-of-bound
      write vulnerability inside structure in VNC client code.
    - debian/patches/libvncclient_CVE-2018-20021.patch: CWE-835: Infinite loop
      vulnerability in VNC client code.
    - debian/patches/libvncclient_CVE-2018-20022.patch: CWE-665: Improper
      Initialization vulnerability.
    - debian/patches/libvncclient_CVE-2018-20023.patch: Improper
      Initialization vulnerability in VNC Repeater client code.
    - debian/patches/libvncclient_CVE-2018-20024.patch: null pointer
      dereference that can result DoS.
    - debian/patches/libvncclient_CVE-2018-20748-1.patch: ignore server-sent
      cut text longer than 1MB
    - debian/patches/libvncclient_CVE-2018-20748-2.patch: ignore server-sent
      reasong strings longer than 1MB
    - debian/patches/libvncclient_CVE-2018-20748-3.patch: fail on server-sent
      desktop name lengths longer than 1MB
    - debian/patches/libvncclient_CVE-2018-20748-4.patch: remove now-useless
      cast
    - debian/patches/libvncserver_CVE-2018-20749.patch: incomplete fix for
      CVE-2018-15127 oob heap writes.
    - debian/patches/libvncserver_CVE-2018-20750.patch: incomplete fix for
      CVE-2018-15127 oob heap writes.
    - debian/patches/libvncserver_CVE-2019-15681.patch: rfbserver: don't leak
      stack memory to the remote.
    - CVE-2018-7225
    - CVE-2018-15127
    - CVE-2018-20019
    - CVE-2018-20020
    - CVE-2018-20021
    - CVE-2018-20022
    - CVE-2018-20023
    - CVE-2018-20024
    - CVE-2018-20748
    - CVE-2018-20749
    - CVE-2018-20750
    - CVE-2019-15681

 -- Mike Salvatore <email address hidden>  Thu, 24 Sep 2020 11:19:00 -0400

Upload details

Uploaded by:
Mike Salvatore
Uploaded to:
Bionic
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
x11
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Bionic updates universe x11
Bionic security universe x11

Downloads

File Size SHA-256 Checksum
italc_3.0.3+dfsg1.orig.tar.xz 1.7 MiB 3156f0a7ef3ca9af888f1e09b76e602cf5d2bc59640f3e9ec75ae930258df425
italc_3.0.3+dfsg1-3ubuntu0.1.debian.tar.xz 74.3 KiB 28a39dda5634e3f61de487900bd802814d4cd9dde72820b157556a787f50ddc9
italc_3.0.3+dfsg1-3ubuntu0.1.dsc 2.6 KiB a07aed65b5927120de6ccce16567ac09ba026e068c2e057f82f84a91f982329c

View changes file

Binary packages built by this source

italc-client: intelligent Teaching And Learning with Computers - client

 iTALC makes it possible to access and guide the activities of students
 from the computer of the teacher. For example, with the help of iTALC
 a teacher can view the contents of students' screens and see if any of
 them need help. If so, the teacher can access the student's desktop and
 provide support; the student can watch the teacher's actions and learn
 from them. Alternatively the teacher can switch into "demo-mode", where
 all the students' screens show the contents of the teacher's screen.
 Furthermore, actions like locking students' screens, killing games,
 powering clients on or off, and much more can all be performed via iTALC.
 .
 This package contains the client software for iTALC, which can be
 controlled using italc-master.

italc-client-dbgsym: debug symbols for italc-client
italc-management-console: intelligent Teaching And Learning with Computers - management console

 iTALC makes it possible to access and guide the activities of students
 from the computer of the teacher. For example, with the help of iTALC
 a teacher can view the contents of students' screens and see if any of
 them need help. If so, the teacher can access the student's desktop and
 provide support; the student can watch the teacher's actions and learn
 from them. Alternatively the teacher can switch into "demo-mode", where
 all the students' screens show the contents of the teacher's screen.
 Furthermore, actions like locking students' screens, killing games,
 powering clients on or off, and much more can all be performed via iTALC.
 .
 This package contains the management console for iTALC, which helps to
 configure and manage iTALC installations.

italc-management-console-dbgsym: debug symbols for italc-management-console
italc-master: intelligent Teaching And Learning with Computers - master

 iTALC makes it possible to access and guide the activities of students
 from the computer of the teacher. For example, with the help of iTALC
 a teacher can view the contents of students' screens and see if any of
 them need help. If so, the teacher can access the student's desktop and
 provide support; the student can watch the teacher's actions and learn
 from them. Alternatively the teacher can switch into "demo-mode", where
 all the students' screens show the contents of the teacher's screen.
 Furthermore, actions like locking students' screens, killing games,
 powering clients on or off, and much more can all be performed via iTALC.
 .
 This package contains the software necessary to observe and control iTALC
 clients provided by the italc-client package.

italc-master-dbgsym: debug symbols for italc-master
libitalccore: intelligent Teaching And Learning with Computers - libraries

 iTALC makes it possible to access and guide the activities of students
 from the computer of the teacher. For example, with the help of iTALC
 a teacher can view the contents of students' screens and see if any of
 them need help. If so, the teacher can access the student's desktop and
 provide support; the student can watch the teacher's actions and learn
 from them. Alternatively the teacher can switch into "demo-mode", where
 all the students' screens show the contents of the teacher's screen.
 Furthermore, actions like locking students' screens, killing games,
 powering clients on or off, and much more can all be performed via iTALC.
 .
 This package provides the common libraries needed for iTALC.

libitalccore-dbgsym: debug symbols for libitalccore