First published: Thu Dec 26 2019(Updated: )
TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow. Vulnerability could be triggered from CopyRectDecoder due to incorrect value checks. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity.
Credit: vulnerability@kaspersky.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tigervnc | <1.10.1 | |
SUSE Linux | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15692 is a vulnerability in TigerVNC version prior to 1.10.1 that allows for a heap buffer overflow.
The severity of CVE-2019-15692 is high with a CVSS score of 7.2.
CVE-2019-15692 can be exploited through network connections.
The affected software is Tigervnc versions prior to 1.10.1 and openSUSE Leap 15.1.
To fix CVE-2019-15692, update your Tigervnc installation to version 1.10.1 or newer.