Buffer overflow in gtk-vnc - CVE-2017-1000044

 

Buffer overflow in gtk-vnc - CVE-2017-1000044

Published: August 3, 2020


Vulnerability identifier: #VU32991
CSH Severity: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2017-1000044
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
gtk-vnc
Software vendor:
Gnome Development Team

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when rendering.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.

External links