Out-of-bounds read in UltraVNC - CVE-2019-8261
Published: November 25, 2019 / Updated: November 27, 2019
UltraVNC
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to sensitive information on the target system.
The vulnerability exists due to a boundary condition in VNC code inside client CoRRE decoder, caused by multiplication overflow. A remote attacker that controls a malicious VNC server can trick a user to connect to it, trigger out-of-bounds read error and read contents of memory on the system.