LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.debian.org/security/2019/dsa-4383 | third party advisory vendor advisory |
https://lists.debian.org/debian-lts-announce/2018/12/msg00017.html | third party advisory mailing list |
https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/12/19/klcert-18-028-libvnc-heap-out-of-bound-write/ | third party advisory |
https://usn.ubuntu.com/3877-1/ | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2019:0059 | third party advisory vendor advisory |
https://lists.debian.org/debian-lts-announce/2019/10/msg00042.html | mailing list |
https://usn.ubuntu.com/4547-1/ | vendor advisory |
https://usn.ubuntu.com/4587-1/ | vendor advisory |