First published: Fri Mar 01 2019(Updated: )
UltraVNC revision 1207 has out-of-bounds read vulnerability in VNC client code inside TextChat module, which results in a denial of service (DoS) condition. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1208.
Credit: vulnerability@kaspersky.com vulnerability@kaspersky.com
Affected Software | Affected Version | How to fix |
---|---|---|
UltraVNC | <1.2.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-8267 is classified as a denial of service (DoS) vulnerability.
To fix CVE-2019-8267, upgrade to UltraVNC revision 1208 or later.
The CVE-2019-8267 vulnerability is caused by an out-of-bounds read in the VNC client code specifically in the TextChat module.
CVE-2019-8267 affects UltraVNC versions up to 1.2.2.3.
Yes, CVE-2019-8267 can be exploited remotely via network connectivity.