First published: Fri Feb 03 2017(Updated: )
It was found that gtk-vnc does not properly check boundaries of subrectangle-containing tiles. A malicious server can use this to overwrite parts of the client memory, potentially leading to code execution under privileges of the user running the VNC client. Upstream bug: <a href="https://bugzilla.gnome.org/show_bug.cgi?id=778048">https://bugzilla.gnome.org/show_bug.cgi?id=778048</a> Upstream patch: <a href="https://git.gnome.org/browse/gtk-vnc/commit/?id=ea0386933214c9178">https://git.gnome.org/browse/gtk-vnc/commit/?id=ea0386933214c9178</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fedoraproject Fedora | =25 | |
Gnome Gtk-vnc | <=0.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.