gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when rendering
It was found that gtk-vnc does not properly check boundaries of subrectangle-containing tiles. A malicious server can use this to overwrite parts of the client memory, potentially leading to code execution under privileges of the user running the VNC client.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=778048
Upstream patch:
https://git.gnome.org/browse/gtk-vnc/commit/?id=ea0386933214c9178