First published: Mon Jan 23 2017(Updated: )
A buffer overflow vulnerability in ModifiablePixelBuffer::fillRect in vncviewer was found allowing malicious VNC server to send crafted RRE message and possibly take control of the TigerVNC viewer. Upstream patch: <a href="https://github.com/TigerVNC/tigervnc/commit/18c020124ff1b2441f714da2017f63dba50720ba">https://github.com/TigerVNC/tigervnc/commit/18c020124ff1b2441f714da2017f63dba50720ba</a> PR: <a href="https://github.com/TigerVNC/tigervnc/pull/399">https://github.com/TigerVNC/tigervnc/pull/399</a> Reference: <a href="http://seclists.org/oss-sec/2017/q1/166">http://seclists.org/oss-sec/2017/q1/166</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tigervnc Tigervnc | <=1.7 | |
redhat/tigervnc | <1.7.1 | 1.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.