Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-15690

Опубликовано: 24 янв. 2025
Источник: debian
EPSS Низкий

Описание

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libvncserverfixed0.9.12+dfsg-9package
libvncserverfixed0.9.11+dfsg-1.3+deb10u3busterpackage
libvncserverfixed0.9.11+dfsg-1.3~deb9u4stretchpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2019/12/20/2

  • https://github.com/LibVNC/libvncserver/issues/381

  • https://github.com/LibVNC/libvncserver/commit/54220248886b5001fbbb9fa73c4e1a2cb9413fed

EPSS

Процентиль: 82%
0.01662
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 1 года назад

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

CVSS3: 9.8
redhat
около 6 лет назад

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

CVSS3: 8.8
nvd
около 1 года назад

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

CVSS3: 8.8
github
около 1 года назад

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

oracle-oval
почти 6 лет назад

ELSA-2020-0920: libvncserver security update (IMPORTANT)

EPSS

Процентиль: 82%
0.01662
Низкий