Severity
9.8CRITICAL
EPSS
0.8%
top 25.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 31
Latest updateMay 13

Description

Heap-based buffer overflow in rfbproto.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message containing a subrectangle outside of the client drawing area.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

Debianlibvncserver< 0.9.11+dfsg-1+3
Ubuntulibvncserver< 0.9.9+dfsg-1ubuntu1.2+1
Debianveyon< 4.1.4+repack1-1+3

🔴Vulnerability Details

5
GHSA
GHSA-96f2-683j-mrm6: Heap-based buffer overflow in rfbproto2022-05-13
OSV
italc vulnerabilities2020-10-20
OSV
libvncserver vulnerabilities2017-01-11
CVEList
CVE-2016-9941: Heap-based buffer overflow in rfbproto2016-12-31
OSV
CVE-2016-9941: Heap-based buffer overflow in rfbproto2016-12-31

📋Vendor Advisories

4
Ubuntu
iTALC vulnerabilities2020-10-20
Ubuntu
LibVNCServer vulnerabilities2017-01-11
Red Hat
libvncserver: Heap-based buffer overflow in rfbproto.c2016-11-14
Debian
CVE-2016-9941: libvncserver - Heap-based buffer overflow in rfbproto.c in LibVNCClient in LibVNCServer before ...2016

💬Community

4
Bugzilla
CVE-2016-9941 CVE-2016-9942 libvncserver: various flaws2017-01-04
Bugzilla
CVE-2016-9941 libvncserver: Heap-based buffer overflow in rfbproto.c2017-01-04
Bugzilla
CVE-2016-9941 CVE-2016-9942 libvncserver: various flaws [fedora-all]2017-01-04
Bugzilla
CVE-2016-9941 CVE-2016-9942 libvncserver: various flaws [epel-5]2017-01-04