First published: Fri Mar 09 2001(Updated: )
Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AT&T WinVNC | <=3.3.3r7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0167 is considered a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2001-0167, you should upgrade to a version of AT&T WinVNC later than 3.3.3r7.
CVE-2001-0167 allows attackers to execute arbitrary commands on affected systems through crafted rfbConnFailed packets.
Users of AT&T WinVNC version 3.3.3r7 and earlier are affected by CVE-2001-0167.
A potential temporary mitigation for CVE-2001-0167 is to block or filter incoming rfbConnFailed packets.