Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-0905

Опубликовано: 10 мая 2011
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.5

Описание

The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when tight encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via crafted dimensions in a framebuffer update request that triggers an out-of-bounds read operation.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

hardy

ignored

end of life
karmic

ignored

end of life
lucid

not-affected

code not present
maverick

not-affected

code not present
natty

not-affected

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

hardy

not-affected

karmic

ignored

end of life
lucid

not-affected

maverick

not-affected

natty

not-affected

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

3.0.2-0ubuntu4
hardy

released

2.22.2-0ubuntu1.1
karmic

ignored

end of life
lucid

released

2.28.2-0ubuntu2.1
maverick

released

2.32.0-0ubuntu1.2
natty

released

2.32.1-0ubuntu2.1
upstream

needs-triage

Показывать по

EPSS

Процентиль: 78%
0.01211
Низкий

3.5 Low

CVSS2

Связанные уязвимости

redhat
больше 14 лет назад

The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when tight encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via crafted dimensions in a framebuffer update request that triggers an out-of-bounds read operation.

nvd
больше 14 лет назад

The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when tight encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via crafted dimensions in a framebuffer update request that triggers an out-of-bounds read operation.

debian
больше 14 лет назад

The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver ...

github
больше 3 лет назад

The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when tight encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via crafted dimensions in a framebuffer update request that triggers an out-of-bounds read operation.

oracle-oval
больше 12 лет назад

ELSA-2013-0169: vino security update (MODERATE)

EPSS

Процентиль: 78%
0.01211
Низкий

3.5 Low

CVSS2