PT-2008-5065 · Echovnc · Echovnc Linux
Published
2008-08-19
·
Updated
2017-08-08
·
CVE-2008-3705
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
EchoVNC Linux versions prior to 1.1.2
Description
A stack-based buffer overflow issue exists in the CLogger::WriteFormated function, located in echoware/Logger.cpp. This allows remote echoServers to execute arbitrary code by sending a large group or user list, which can be described as a "very crowded echoServer" attack.
Recommendations
For EchoVNC Linux versions prior to 1.1.2, update to version 1.1.2 or later to resolve the issue. As a temporary workaround, consider restricting the size of group or user lists received from remote echoServers to prevent exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Echovnc Linux