REDHAT-BUG-1418944: Low severity gtk-vnc vulnerability
It was found that gtk-vnc does not properly check boundaries of subrectangle-containing tiles. A malicious server can use this to overwrite parts of the client memory, potentially leading to code execution under privileges of the user running the VNC client.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=778048
Upstream patch:
https://git.gnome.org/browse/gtk-vnc/commit/?id=ea0386933214c9178
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1418944?
The severity of REDHAT-BUG-1418944 is high due to the potential for code execution and memory corruption.
How do I fix REDHAT-BUG-1418944?
To fix REDHAT-BUG-1418944, update gtk-vnc to the latest patched version as recommended by the vendor.
What are the potential impacts of REDHAT-BUG-1418944?
The potential impacts of REDHAT-BUG-1418944 include unauthorized code execution and compromise of user privileges.
Who is affected by REDHAT-BUG-1418944?
Users running a vulnerable version of gtk-vnc are affected by REDHAT-BUG-1418944.
What causes the vulnerability in REDHAT-BUG-1418944?
REDHAT-BUG-1418944 is caused by improper boundary checks in the handling of subrectangle-containing tiles.