Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11501
HistoryJan 15, 2019 - 9:02 a.m.

Denial Of Service (DoS)

2019-01-1509:02:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

EPSS

0.01

Percentile

83.7%

libvncserver is vulnerable to denial of service (DoS) attacks. The vulnerability exists as an integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow. .

References