Note:
This project will be discontinued after December 13, 2021. [more]
2019-10-29
TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.
Products | Tightvnc |
Type | Out-of-bounds Write (CWE-787) |
First patch | - None (likely due to unavailable code) |
Links |
• https://www.openwall.com/lists/oss-security/2018/12/10/5
• https://us-cert.cisa.gov/ics/advisories/icsa-20-343-08 • https://cert-portal.siemens.com/productcert/pdf/ssa-478893.pdf • https://lists.debian.org/debian-lts-announce/2019/12/msg00028.html |