CVE-2001-0168: Buffer Overflow
Published Mar 9, 2001
·Updated
Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the DebugLevel registry key is greater than 0.
Affected Software
1 affected component
Att WinVNC<=3.3.3r7
Remediation
Patch Available
Event History
Mar 9, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0168?
CVE-2001-0168 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2001-0168?
To fix CVE-2001-0168, upgrade to a version of AT&T WinVNC that is later than 3.3.3r7.
3
What is the cause of CVE-2001-0168?
CVE-2001-0168 is caused by a buffer overflow vulnerability in the AT&T WinVNC server.
4
Who is affected by CVE-2001-0168?
Users running AT&T WinVNC versions 3.3.3r7 and earlier with DebugLevel registry key set above 0 are affected.
5
What can attackers achieve with CVE-2001-0168?
Attackers can execute arbitrary commands on the server due to the buffer overflow vulnerability present in CVE-2001-0168.