CVE-2016-9941: Buffer Overflow
Published Dec 31, 2016
·Updated
Heap-based buffer overflow in rfbproto.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message containing a subrectangle outside of the client drawing area.
Affected Software
3 affected componentsFixes available
Libvncserver Project Libvncserver<=0.9.10
debian/libvncserver
0.9.13+dfsg-2+deb11u10.9.14+dfsg-10.9.15+dfsg-1
debian/veyon
4.5.3+repack1-14.7.5+repack1-14.7.5+repack1-1.24.9.5+repack1-2
Remediation
Event History
Dec 31, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:23 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:18 AM
RemedyDescriptionSeverityAffected Software
May 2, 2025
Data Sourced
via Debian·03:46 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2016-9941.
2
What is the severity level of CVE-2016-9941?
CVE-2016-9941 has a severity level of critical.
3
Which software versions are affected by CVE-2016-9941?
CVE-2016-9941 affects LibVNCServer versions before 0.9.11.
4
How does CVE-2016-9941 impact the affected software?
CVE-2016-9941 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code through a crafted FramebufferUpdate message.
5
Are there any available fixes or patches for CVE-2016-9941?
Yes, updates are available for LibVNCServer to address CVE-2016-9941. Users should update to version 0.9.11 or later.