CVE-2011-0904: Buffer Overflow

Published Apr 7, 2011
·
Updated

An out of bounds read flaw was found in the way vino, remote desktop system for GNOME processed certain framebuffer update requests from VNC client, when raw encoding was used. An attacker could use this flaw to send a specially-crafted request to vino, causing it to crash.

Upstream bug report: [1] https://bugzilla.gnome.org/showbug.cgi?id=641802

Relevant upstream commits (for gnome-2-28, gnome-2-30, gnome-2-32, gnome-3-0 and master branches):

[2] http://git.gnome.org/browse/vino/commit/?id=dff52694a384fe95195f2211254026b752d63ec4 [3] http://git.gnome.org/browse/vino/commit/?id=0c2c9175963fc56bf2af10e42867181332f96ce0 [4] http://git.gnome.org/browse/vino/commit/?id=e17bd4e369f90748654e31a4867211dc7610975d [5] http://git.gnome.org/browse/vino/commit/?id=456dadbb5c5971d3448763a44c05b9ad033e522f [6] http://git.gnome.org/browse/vino/commit/?id=8beefcf7792d343c10c919ee0c928c81f73b1279

Other sources

The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when raw encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via a large (1) X position or (2) Y position value in a framebuffer update request that triggers an out-of-bounds memory access, related to the rfbTranslateNone and rfbSendRectEncodingRaw functions.

MITRE

Affected Software

71 affected components
David King Vino=2.23.5
David King Vino=2.21.92
David King Vino=2.23
David King Vino=2.17.92
David King Vino=2.19.5
David King Vino=2.32.0
David King Vino=2.19
David King Vino=2.27.5
David King Vino=3.0.1
David King Vino=2.22
David King Vino=2.32.1
David King Vino=2.25.91
David King Vino=2.23.92
David King Vino=2.21.2
David King Vino=2.25.3
David King Vino=2.18
David King Vino=2.21.1
David King Vino=2.10
David King Vino=2.7.92
David King Vino=2.24.1
David King Vino=2.7.4.91
David King Vino=2.28.2
David King Vino=2.26.2
David King Vino=2.7.3.1
David King Vino=2.19.92
David King Vino=2.11
David King Vino=2.25.92
David King Vino=3.0.0
David King Vino=2.20.1
David King Vino=2.27.90
David King Vino=2.27
David King Vino=2.16
David King Vino=3.1
David King Vino=2.7.3
David King Vino=2.7.4
David King Vino=2.13.5
David King Vino=2.24
David King Vino=2.28.1
David King Vino=2.7.4.90
David King Vino=2.23.91
David King Vino=2.26
David King Vino=2.17.4
David King Vino=2.25.4
David King Vino=2.27.92
David King Vino=2.14
David King Vino=2.9
David King Vino=2.13
David King Vino=2.21
David King Vino=2.26.1
David King Vino=2.28
David King Vino=2.17
David King Vino=2.7
David King Vino=2.25.90
David King Vino=2.9.2
David King Vino=2.12
David King Vino=2.21.91
David King Vino=2.20
David King Vino=2.21.3
David King Vino=2.17.5
David King Vino=2.25
David King Vino=2.27.91
David King Vino=2.8
David King Vino=2.25.5
David King Vino=2.22.2
David King Vino=2.21.90
David King Vino=2.18.1
David King Vino=2.17.2
David King Vino=2.22.1
David King Vino=2.23.90
David King Vino=2.19.90
David King Vino=2.15

Event History

Apr 7, 2011
Data Sourced
12:48 PM
DescriptionSeverityAffected Software
May 10, 2011
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2011-0904?

CVE-2011-0904 has a severity rating that indicates it could lead to potential denial-of-service attacks on the affected systems.

2

How do I fix CVE-2011-0904?

To fix CVE-2011-0904, update the Vino remote desktop software to a patched version provided by the vendor.

3

What versions of Vino are affected by CVE-2011-0904?

CVE-2011-0904 affects multiple versions of Vino, including versions 2.10 through 3.1.

4

Can CVE-2011-0904 be exploited remotely?

Yes, CVE-2011-0904 can be exploited remotely through specially crafted framebuffer update requests from a VNC client.

5

What are the potential impacts of CVE-2011-0904?

The potential impacts of CVE-2011-0904 include application crashes and subsequent denial of service for users trying to connect remotely.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203