Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-5884

Опубликовано: 01 фев. 2017
Источник: redhat
CVSS3: 3.1

Описание

gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.

It was found that gtk-vnc lacked proper bounds checking while processing messages using RRE, hextile, or copyrect encodings. A remote malicious VNC server could use this flaw to crash VNC viewers which are based on the gtk-vnc library.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gtk-vncWill not fix
Red Hat Enterprise Linux 6gtk-vncWill not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerWill not fix
Red Hat Enterprise Linux 7gtk-vncFixedRHSA-2017:225801.08.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1418944gtk-vnc: Improper check of framebuffer boundaries when processing a tile

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.

CVSS3: 7.8
nvd
больше 8 лет назад

gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.

CVSS3: 7.8
debian
больше 8 лет назад

gtk-vnc before 0.7.0 does not properly check boundaries of subrectangl ...

CVSS3: 7.8
github
больше 3 лет назад

gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.

suse-cvrf
около 4 лет назад

Security update for gtk-vnc

3.1 Low

CVSS3