Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-6051

Опубликовано: 23 сент. 2014
Источник: redhat
CVSS2: 6
EPSS Низкий

Описание

Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow.

An integer overflow flaw, leading to a heap-based buffer overflow, was found in the way screen sizes were handled by LibVNCServer. A malicious VNC server could use this flaw to cause a client to crash or, potentially, execute arbitrary code in the client.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kdenetworkNot affected
Red Hat Enterprise Linux 6kdenetworkNot affected
Red Hat Enterprise Linux 7kdenetworkNot affected
Red Hat Enterprise Linux 6libvncserverFixedRHSA-2014:182611.11.2014
Red Hat Enterprise Linux 6.5 Extended Update SupportlibvncserverFixedRHSA-2015:011302.02.2015
Red Hat Enterprise Linux 7libvncserverFixedRHSA-2014:182611.11.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1144287libvncserver: integer overflow flaw, leading to a heap-based buffer overflow in screen size handling

EPSS

Процентиль: 91%
0.06605
Низкий

6 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow.

nvd
около 11 лет назад

Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow.

debian
около 11 лет назад

Integer overflow in the MallocFrameBuffer function in vncviewer.c in L ...

github
больше 3 лет назад

Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow.

CVSS3: 7.3
fstec
больше 11 лет назад

Уязвимость функции MallocFrameBuffer кроссплатформенной библиотеки LibVNCServer, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 91%
0.06605
Низкий

6 Medium

CVSS2

Уязвимость CVE-2014-6051