Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-0905

Опубликовано: 02 мая 2011
Источник: redhat
CVSS2: 3.5
EPSS Низкий

Описание

The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when tight encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via crafted dimensions in a framebuffer update request that triggers an out-of-bounds read operation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4kdenetworkWill not fix
Red Hat Enterprise Linux 4vinoWill not fix
Red Hat Enterprise Linux 5kdenetworkWill not fix
Red Hat Enterprise Linux 5vinoWill not fix
Red Hat Enterprise Linux 6kdenetworkNot affected
Red Hat Enterprise Linux 6libvncserverNot affected
Red Hat Enterprise Linux 6vinoFixedRHSA-2013:016921.01.2013

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=694456vino: Out of bounds read flaw by processing certain client tight encoding framebuffer update requests

EPSS

Процентиль: 78%
0.01211
Низкий

3.5 Low

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when tight encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via crafted dimensions in a framebuffer update request that triggers an out-of-bounds read operation.

nvd
больше 14 лет назад

The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when tight encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via crafted dimensions in a framebuffer update request that triggers an out-of-bounds read operation.

debian
больше 14 лет назад

The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver ...

github
больше 3 лет назад

The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when tight encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via crafted dimensions in a framebuffer update request that triggers an out-of-bounds read operation.

oracle-oval
больше 12 лет назад

ELSA-2013-0169: vino security update (MODERATE)

EPSS

Процентиль: 78%
0.01211
Низкий

3.5 Low

CVSS2