Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8240

Опубликовано: 10 окт. 2014
Источник: redhat
CVSS2: 6.8

Описание

Integer overflow in TigerVNC allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to screen size handling, which triggers a heap-based buffer overflow, a similar issue to CVE-2014-6051.

An integer overflow flaw, leading to a heap-based buffer overflow, was found in the way TigerVNC handled screen sizes. A malicious VNC server could use this flaw to cause a client to crash or, potentially, execute arbitrary code on the client.

Отчет

This issue affects the version of tigervnc as shipped with Red Hat Enterprise Linux 5 and 6. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates of Red Hat Enterprise Linux 5 and 6.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5vncWill not fix
Red Hat Enterprise Linux 6tigervncWill not fix
Red Hat Enterprise Linux 7tigervncFixedRHSA-2015:223319.11.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1151307tigervnc: integer overflow flaw, leading to a heap-based buffer overflow in screen size handling

6.8 Medium

CVSS2

Связанные уязвимости

nvd
почти 11 лет назад

Integer overflow in TigerVNC allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to screen size handling, which triggers a heap-based buffer overflow, a similar issue to CVE-2014-6051.

debian
почти 11 лет назад

Integer overflow in TigerVNC allows remote VNC servers to cause a deni ...

github
больше 3 лет назад

Integer overflow in TigerVNC allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to screen size handling, which triggers a heap-based buffer overflow, a similar issue to CVE-2014-6051.

oracle-oval
почти 10 лет назад

ELSA-2015-2233: tigervnc security, bug fix, and enhancement update (MODERATE)

6.8 Medium

CVSS2