PT-2019-5759 · Tigervnc+4 · Tigervnc+4

Pavel Cheremushkin

·

Publicado

2019-12-20

·

Atualizado

2024-06-15

·

CVE-2019-15693

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TigerVNC versions prior to 1.10.1
Description The issue is related to a heap buffer overflow in the TightDecoder::FilterGradient function, which could potentially lead to remote code execution. This can be exploited via network connectivity, allowing a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For TigerVNC versions prior to 1.10.1, update to version 1.10.1 or later to resolve the issue. As a temporary workaround, consider restricting network connectivity to minimize the risk of exploitation.

Exploit

Correção

RCE

Memory Corruption

Heap Based Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-2103
ALT-PU-2020-3345
ALT-PU-2021-1185
BDU:2021-01455
CESA-2020_1497
CESA-2020_3875
CVE-2019-15693
MGASA-2020-0042
OPENSUSE-SU-2020:0087-1
OPENSUSE-SU-2020_0087-1
OPENSUSE-SU-2024:10591-1
RHSA-2020:1497
RHSA-2020:3875
RHSA-2020_1497
RHSA-2020_3875
SUSE-SU-2020:0112-1
SUSE-SU-2020:0113-1
SUSE-SU-2020:0159-1
SUSE-SU-2020:0266-1
SUSE-SU-2020:1749-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Tigervnc