CVE-2017-5884
published 2017-02-28CVE-2017-5884: gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x…
PriorityP341high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
2.24%
80.8th percentile
gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gtk-vnc | < gtk-vnc 0.6.0-3 (bookworm) | gtk-vnc 0.6.0-3 (bookworm) |
| fedoraproject | fedora | — | — |
| gnome | gtk-vnc | <= 0.6.0 | — |
| gnome | gtk-vnc | >= 0 < 0.6.0-3 | 0.6.0-3 |
| gnome | gtk-vnc | >= 0 < 0.6.0-3 | 0.6.0-3 |
| gnome | gtk-vnc | >= 0 < 0.6.0-3 | 0.6.0-3 |
| gnome | gtk-vnc | >= 0 < 0.6.0-3 | 0.6.0-3 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
gtk-vnc vulnerabilities
vendor_ubuntu·2017-02-20
CVE-2017-5884 gtk-vnc vulnerabilities
Title: gtk-vnc vulnerabilities
Summary: gtk-vnc could be made to crash or run programs if it received specially
crafted network traffic.
It was discovered that gtk-vnc incorrectly validated certain data. A
malicious server could use this issue to cause gtk-vnc to crash, resulting
in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gtk-vnc: Improper check of framebuffer boundaries when processing a tile
vendor_redhat·2017-02-01·CVSS 7.8
CVE-2017-5884 [HIGH] CWE-787 gtk-vnc: Improper check of framebuffer boundaries when processing a tile
gtk-vnc: Improper check of framebuffer boundaries when processing a tile
gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.
It was found that gtk-vnc lacked proper bounds checking while processing messages using RRE, hextile, or copyrect encodings. A remote malicious VNC server could use this flaw to crash VNC viewers which are based on the gtk-vnc library.
Package: gtk-vnc (Red Hat Enterprise Linux 5) - Will not fix
Package: gtk-vnc (Red Hat Enterprise Linux 6) - Will not fix
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Will not fix
Debian
CVE-2017-5884: gtk-vnc - gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containi...
vendor_debian·2017·CVSS 7.8
CVE-2017-5884 [HIGH] CVE-2017-5884: gtk-vnc - gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containi...
gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.
Scope: local
bookworm: resolved (fixed in 0.6.0-3)
bullseye: resolved (fixed in 0.6.0-3)
forky: resolved (fixed in 0.6.0-3)
sid: resolved (fixed in 0.6.0-3)
trixie: resolved (fixed in 0.6.0-3)
GHSA
GHSA-2gcq-vqxg-c7xv: gtk-vnc before 0
ghsa_unreviewed·2022-05-14
CVE-2017-5884 [HIGH] CWE-118 GHSA-2gcq-vqxg-c7xv: gtk-vnc before 0
gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.
OSV
CVE-2017-5884: gtk-vnc before 0
osv·2017-02-28·CVSS 7.8
CVE-2017-5884 [HIGH] CVE-2017-5884: gtk-vnc before 0
gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5884 CVE-2017-5885 gtk-vnc: various flaws [fedora-all]
bugzilla·2017-02-03·CVSS 7.8
CVE-2017-5884 [HIGH] CVE-2017-5884 CVE-2017-5885 gtk-vnc: various flaws [fedora-all]
CVE-2017-5884 CVE-2017-5885 gtk-vnc: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While
Bugzilla
CVE-2017-5884 CVE-2017-5885 mingw-gtk-vnc: various flaws [fedora-all]
bugzilla·2017-02-03·CVSS 7.8
CVE-2017-5884 [HIGH] CVE-2017-5884 CVE-2017-5885 mingw-gtk-vnc: various flaws [fedora-all]
CVE-2017-5884 CVE-2017-5885 mingw-gtk-vnc: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2017-5884 gtk-vnc: Improper check of framebuffer boundaries when processing a tile
bugzilla·2017-02-03·CVSS 7.8
CVE-2017-5884 [HIGH] CVE-2017-5884 gtk-vnc: Improper check of framebuffer boundaries when processing a tile
CVE-2017-5884 gtk-vnc: Improper check of framebuffer boundaries when processing a tile
It was found that gtk-vnc does not properly check boundaries of subrectangle-containing tiles. A malicious server can use this to overwrite parts of the client memory, potentially leading to code execution under privileges of the user running the VNC client.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=778048
Upstream patch:
https://git.gnome.org/browse/gtk-vnc/commit/?id=ea0386933214c9178
Discussion:
Created gtk-vnc tracking bugs for this issue:
Affects: fedora-all [bug 1418955]
---
Created mingw-gtk-vnc tracking bugs for this issue:
Affects: fedora-all [bug 1418956]
---
CVE assignment:
http://openwall.com/lists/oss-security/2017/02/05/5
CVE covers all issues mentioned in http
http://www.openwall.com/lists/oss-security/2017/02/03/5http://www.openwall.com/lists/oss-security/2017/02/05/5http://www.securityfocus.com/bid/96016https://access.redhat.com/errata/RHSA-2017:2258https://bugzilla.gnome.org/show_bug.cgi?id=778048https://git.gnome.org/browse/gtk-vnc/commit/?id=ea0386933214c9178aaea9f2f85049ea3fa3e14ahttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LGPQ5MQR6SN4DYTEFACHP2PP5RR26KYK/http://www.openwall.com/lists/oss-security/2017/02/03/5http://www.openwall.com/lists/oss-security/2017/02/05/5http://www.securityfocus.com/bid/96016https://access.redhat.com/errata/RHSA-2017:2258https://bugzilla.gnome.org/show_bug.cgi?id=778048https://git.gnome.org/browse/gtk-vnc/commit/?id=ea0386933214c9178aaea9f2f85049ea3fa3e14ahttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LGPQ5MQR6SN4DYTEFACHP2PP5RR26KYK/
2017-02-28
Published