PT-2019-4940 · Ultravnc · Ultravnc
Publicado
2019-03-05
·
Atualizado
2020-06-12
·
CVE-2019-8266
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UltraVNC revision 1207
Description
The issue is related to improper usage of the
ClientConnection::Copybuffer function in the VNC client code, which can result in out-of-bounds access and potentially allow code execution. This can be exploited via network connectivity, and user interaction is required to trigger the issue. The exploitation of this vulnerability may allow a remote attacker to execute arbitrary code.Recommendations
For UltraVNC revision 1207, update to revision 1208 to resolve the issue. As a temporary workaround, consider restricting network connectivity to minimize the risk of exploitation until the update can be applied.
Correção
Access of Memory Location After End of Buffer
Memory Corruption
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ultravnc