CVE-2001-0167: Buffer Overflow
Published Mar 9, 2001
·Updated
Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string.
Affected Software
1 affected component
Att WinVNC<=3.3.3r7
Remediation
Patch Available
Event History
Mar 9, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0167?
CVE-2001-0167 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2001-0167?
To fix CVE-2001-0167, you should upgrade to a version of AT&T WinVNC later than 3.3.3r7.
3
What types of attacks can occur due to CVE-2001-0167?
CVE-2001-0167 allows attackers to execute arbitrary commands on affected systems through crafted rfbConnFailed packets.
4
Who is affected by CVE-2001-0167?
Users of AT&T WinVNC version 3.3.3r7 and earlier are affected by CVE-2001-0167.
5
Is there any temporary mitigation for CVE-2001-0167?
A potential temporary mitigation for CVE-2001-0167 is to block or filter incoming rfbConnFailed packets.