PT-2009-1012 · Realvnc+1 · Realvnc Vnc Free Edition+4

Published

2009-01-16

·

Updated

2022-06-10

·

CVE-2008-4770

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions RealVNC VNC Free Edition versions 4.0 through 4.1.2 RealVNC VNC Enterprise Edition versions E4.0 through E4.4.2 RealVNC VNC Personal Edition versions P4.0 through P4.4.2
Description The issue allows remote VNC servers to execute arbitrary code via crafted RFB protocol data, related to "encoding type." This is due to a problem in the CMsgReader::readRect function in the VNC Viewer component. The vulnerability can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information.
Recommendations For RealVNC VNC Free Edition versions 4.0 through 4.1.2, update to a version outside of this range to resolve the issue. For RealVNC VNC Enterprise Edition versions E4.0 through E4.4.2, update to a version outside of this range to resolve the issue. For RealVNC VNC Personal Edition versions P4.0 through P4.4.2, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the VNC Viewer component until a patch is available.

Fix

RCE

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02031
BDU:2022-06447
CVE-2008-4770
DSA-1716-1
RHSA-2009:0261
RHSA-2009_0261

Affected Products

Realvnc Vnc Enterprise Edition
Realvnc Vnc Free Edition
Realvnc Vnc Personal Edition
Red Hat
Vnc Viewer