Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-5885

Опубликовано: 01 фев. 2017
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.

An integer overflow flaw was found in gtk-vnc. A remote malicious VNC server could use this flaw to crash VNC viewers which are based on the gtk-vnc library.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gtk-vncWill not fix
Red Hat Enterprise Linux 6gtk-vncWill not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerWill not fix
Red Hat Enterprise Linux 7gtk-vncFixedRHSA-2017:225801.08.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1418952gtk-vnc: Integer overflow when processing SetColorMapEntries

EPSS

Процентиль: 71%
0.0065
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.

CVSS3: 9.8
nvd
около 9 лет назад

Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.

CVSS3: 9.8
debian
около 9 лет назад

Multiple integer overflows in the (1) vnc_connection_server_message an ...

CVSS3: 9.8
github
почти 4 года назад

Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.

suse-cvrf
больше 4 лет назад

Security update for gtk-vnc

EPSS

Процентиль: 71%
0.0065
Низкий

3.1 Low

CVSS3