CVE-2019-8269: Buffer Overflow
Published Mar 1, 2019
·Updated
UltraVNC revision 1206 has stack-based Buffer overflow vulnerability in VNC client code inside FileTransfer module, which leads to a denial of service (DoS) condition. This attack appear to be exploitable via network connectivity. This vulnerability has been fixed in revision 1207.
Affected Software
4 affected components
Uvnc Ultravnc<1.2.2.3
Siemens Sinumerik Access Mymachine\/p2p<4.8
Siemens Sinumerik Pcu Base Win10 Software\/ipc<14.00
Siemens Sinumerik Pcu Base Win7 Software\/ipc<=12.01
Event History
Mar 8, 2019
CVE Published
11:29 PM
Data Sourced
via NVD·11:29 PM
DescriptionSeverityWeaknessAffected Software
Mar 9, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-8269?
CVE-2019-8269 is classified as a moderate severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2019-8269?
To fix CVE-2019-8269, update to UltraVNC revision 1207 or later.
3
What type of vulnerability is CVE-2019-8269?
CVE-2019-8269 is a stack-based buffer overflow vulnerability found in the VNC client code.
4
Can CVE-2019-8269 be exploited remotely?
Yes, CVE-2019-8269 can be exploited via network connectivity.
5
Which software versions are affected by CVE-2019-8269?
CVE-2019-8269 affects UltraVNC versions up to 1.2.2.3, as well as specific versions of Siemens Sinumerik products.