CVE-2016-9942: Buffer Overflow
Heap-based buffer overflow in ultra.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message with the Ultra type tile, such that the LZO payload decompressed length exceeds what is specified by the tile dimensions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2016-9942?
CVE-2016-9942 is a heap-based buffer overflow vulnerability in LibVNCServer that allows remote servers to cause a denial of service or execute arbitrary code.
How does CVE-2016-9942 affect LibVNCClient?
CVE-2016-9942 affects LibVNCClient in LibVNCServer versions before 0.9.11.
What is the severity of CVE-2016-9942?
CVE-2016-9942 has a severity rating of 9.8 (Critical).
How can CVE-2016-9942 be fixed?
To fix CVE-2016-9942, update to LibVNCServer version 0.9.11 or later.
Where can I find more information about CVE-2016-9942?
More information about CVE-2016-9942 can be found at the following references: [link1](https://github.com/LibVNC/libvncserver/pull/137), [link2](https://github.com/LibVNC/libvncserver/pull/137/commits/5fff4353f66427b467eb29e5fdc1da4f2be028bb), [link3](https://security-tracker.debian.org/tracker/CVE-2016-9942).