Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-5884

Опубликовано: 28 фев. 2017
Источник: debian

Описание

gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gtk-vncfixed0.6.0-3package
gtk-vncno-dsajessiepackage

Примечания

  • Scope of the CVE is all of https://bugzilla.gnome.org/show_bug.cgi?id=778048#c1

  • http://openwall.com/lists/oss-security/2017/02/05/5

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.

CVSS3: 3.1
redhat
почти 9 лет назад

gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.

CVSS3: 7.8
nvd
больше 8 лет назад

gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.

CVSS3: 7.8
github
больше 3 лет назад

gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.

suse-cvrf
около 4 лет назад

Security update for gtk-vnc