PT-2009-1012 · Realvnc+1 · Realvnc Vnc Free Edition+4

Publicado

2009-01-16

·

Atualizado

2022-06-10

·

CVE-2008-4770

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions RealVNC VNC Free Edition versions 4.0 through 4.1.2 RealVNC VNC Enterprise Edition versions E4.0 through E4.4.2 RealVNC VNC Personal Edition versions P4.0 through P4.4.2
Description The issue allows remote VNC servers to execute arbitrary code via crafted RFB protocol data, related to "encoding type." This is due to a problem in the CMsgReader::readRect function in the VNC Viewer component. The vulnerability can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information.
Recommendations For RealVNC VNC Free Edition versions 4.0 through 4.1.2, update to a version outside of this range to resolve the issue. For RealVNC VNC Enterprise Edition versions E4.0 through E4.4.2, update to a version outside of this range to resolve the issue. For RealVNC VNC Personal Edition versions P4.0 through P4.4.2, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the VNC Viewer component until a patch is available.

Correção

RCE

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02031
BDU:2022-06447
CVE-2008-4770
DSA-1716-1
RHSA-2009:0261
RHSA-2009_0261

Produtos afetados

Realvnc Vnc Enterprise Edition
Realvnc Vnc Free Edition
Realvnc Vnc Personal Edition
Red Hat
Vnc Viewer