CVE-2019-8258: Buffer Overflow
Published Mar 5, 2019
·Updated
UltraVNC revision 1198 has a heap buffer overflow vulnerability in VNC client code which results code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
Affected Software
4 affected components
Uvnc Ultravnc<1.2.2.3
Siemens Sinumerik Access Mymachine\/p2p<4.8
Siemens Sinumerik Pcu Base Win10 Software\/ipc<14.00
Siemens Sinumerik Pcu Base Win7 Software\/ipc<=12.01
Event History
Mar 5, 2019
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-8258?
CVE-2019-8258 is a critical vulnerability that allows for potential code execution due to a heap buffer overflow.
2
How do I fix CVE-2019-8258?
To fix CVE-2019-8258, upgrade to UltraVNC revision 1199 or later.
3
Which software is affected by CVE-2019-8258?
CVE-2019-8258 affects UltraVNC versions prior to 1.2.2.3 and multiple Siemens Sinumerik software products.
4
What type of vulnerability is CVE-2019-8258?
CVE-2019-8258 is classified as a heap buffer overflow vulnerability in the VNC client code.
5
Is CVE-2019-8258 exploitable remotely?
Yes, CVE-2019-8258 can be exploited via network connectivity.