Note:
This project will be discontinued after December 13, 2021. [more]
2019-10-29
TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.
Products | Tightvnc |
Type | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') (CWE-120) |
First patch | - None (likely due to unavailable code) |
Links |
• https://lists.debian.org/debian-lts-announce/2019/12/msg00028.html
• https://us-cert.cisa.gov/ics/advisories/icsa-20-343-08 • https://www.openwall.com/lists/oss-security/2018/12/10/5 • https://cert-portal.siemens.com/productcert/pdf/ssa-478893.pdf |