LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code execution
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.debian.org/security/2019/dsa-4383 | third party advisory vendor advisory |
https://lists.debian.org/debian-lts-announce/2018/12/msg00017.html | third party advisory mailing list |
https://usn.ubuntu.com/3877-1/ | third party advisory vendor advisory |
https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/12/19/klcert-18-030-libvnc-heap-out-of-bound-write/ | third party advisory |
https://security.gentoo.org/glsa/201908-05 | vendor advisory |
https://lists.debian.org/debian-lts-announce/2019/10/msg00042.html | mailing list |
https://lists.debian.org/debian-lts-announce/2019/11/msg00033.html | mailing list |
https://security.gentoo.org/glsa/202006-06 | vendor advisory |
https://usn.ubuntu.com/4547-1/ | vendor advisory |
https://usn.ubuntu.com/4547-2/ | vendor advisory |
https://usn.ubuntu.com/4587-1/ | vendor advisory |