CVE-2014-8240: Buffer Overflow
Integer overflow in TigerVNC allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to screen size handling, which triggers a heap-based buffer overflow, a similar issue to CVE-2014-6051.
Other sources
This issue was discovered by Tim Waugh of Red Hat. Tigervnc is affected by same thing as in CVE-2014-6051. Integer overflaw leading to a heap-based buffer overflow was found in the way screen sizes were handled. A Malicious VNC server could use this flaw to cause a client to crash or, potentially, execute arbitrary code on the client.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8240?
CVE-2014-8240 is classified as a high severity vulnerability due to its potential to cause denial of service and possible arbitrary code execution.
How do I fix CVE-2014-8240?
To fix CVE-2014-8240, upgrade TigerVNC to the latest version that has addressed this vulnerability.
Who discovered CVE-2014-8240?
CVE-2014-8240 was discovered by Tim Waugh.
What type of attack does CVE-2014-8240 enable?
CVE-2014-8240 enables remote attackers to crash the VNC service and potentially execute arbitrary code.
Which versions of TigerVNC are affected by CVE-2014-8240?
Versions 0.0.90, 0.0.91, 1.0.0, 1.0.1, and 1.1.0 of TigerVNC are affected by CVE-2014-8240.