[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250039

 
 

909

 
 

195882

 
 

282

Paid content will be excluded from the download.


Download | Alert*


CVE-2017-5885
Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.

CVE-2017-5884
gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.

*OVAL
oval:org.secpod.oval:def:703474
CPE    4
cpe:/o:ubuntu:ubuntu_linux:14.04
cpe:/a:gnome:libgtk-vnc-2.0-0
cpe:/o:ubuntu:ubuntu_linux:12.04
cpe:/a:gnome:libgtk-vnc-1.0-0
...

© SecPod Technologies