CVE-2019-8263: Buffer Overflow
UltraVNC revision 1205 has stack-based buffer overflow vulnerability in VNC client code inside ShowConnInfo routine, which leads to a denial of service (DoS) condition. This attack appear to be exploitable via network connectivity. User interaction is required to trigger this vulnerability. This vulnerability has been fixed in revision 1206.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-8263?
CVE-2019-8263 has a high severity level due to its potential for causing a denial of service (DoS) condition.
How do I fix CVE-2019-8263?
To fix CVE-2019-8263, users should update affected software to versions that have addressed this vulnerability.
What types of software are affected by CVE-2019-8263?
CVE-2019-8263 affects various software including UltraVNC and several Siemens products like SINAMICS and SIMATIC HMI panels.
Is user interaction required to exploit CVE-2019-8263?
Yes, user interaction is required to trigger the stack-based buffer overflow vulnerability in CVE-2019-8263.
Can CVE-2019-8263 be exploited remotely?
Yes, CVE-2019-8263 can be exploited remotely due to the VNC client code that processes network data.