PT-2026-27460 · Unknown · Libvncserver
Y637F9Qq2X
·
Published
2026-03-24
·
Updated
2026-05-09
·
CVE-2026-32853
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
LibVNCServer versions prior to commit 009008e
LibVNCServer version 0.9.15
Description
The software contains a heap out-of-bounds read issue in the UltraZip encoding handler. A malicious VNC server can exploit this to cause information disclosure or application crash. The issue is due to improper bounds checking in the
HandleUltraZipBPP() function. Attackers can manipulate subrectangle header counts to read beyond the allocated heap buffer.Recommendations
Update to a version after commit 009008e.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libvncserver