REDHAT-BUG-1144293: Buffer Overflow
Two stack-based buffer overflow flaws were reported in LibVNCServer's file transfer handling. A VNC client could use these flaws to cause the VNC server to crash or, potentially, execute arbitrary code.
Upstream commits:
https://github.com/newsoft/libvncserver/commit/06ccdf016154fde8eccb5355613ba04c59127b2e
https://github.com/newsoft/libvncserver/commit/f528072216dec01cee7ca35d94e171a3b909e677
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1144293?
REDHAT-BUG-1144293 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix REDHAT-BUG-1144293?
To fix REDHAT-BUG-1144293, update the LibVNCServer to the latest version where the buffer overflow vulnerabilities have been addressed.
What systems are affected by REDHAT-BUG-1144293?
REDHAT-BUG-1144293 affects systems running vulnerable versions of LibVNCServer.
What can an attacker accomplish with REDHAT-BUG-1144293?
An attacker exploiting REDHAT-BUG-1144293 could crash the VNC server or potentially execute arbitrary code.
Is there a workaround for REDHAT-BUG-1144293?
There is no specific workaround for REDHAT-BUG-1144293; the best course of action is to apply the necessary updates to LibVNCServer.