CVE-2017-5885
published 2017-02-28CVE-2017-5885: Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a…
PriorityP350critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.98%
91.3th percentile
Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gtk-vnc | < gtk-vnc 0.6.0-3 (bookworm) | gtk-vnc 0.6.0-3 (bookworm) |
| fedoraproject | fedora | — | — |
| gnome | gtk-vnc | <= 0.6.0 | — |
| gnome | gtk-vnc | >= 0 < 0.6.0-3 | 0.6.0-3 |
| gnome | gtk-vnc | >= 0 < 0.6.0-3 | 0.6.0-3 |
| gnome | gtk-vnc | >= 0 < 0.6.0-3 | 0.6.0-3 |
| gnome | gtk-vnc | >= 0 < 0.6.0-3 | 0.6.0-3 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
gtk-vnc vulnerabilities
vendor_ubuntu·2017-02-20
CVE-2017-5884 gtk-vnc vulnerabilities
Title: gtk-vnc vulnerabilities
Summary: gtk-vnc could be made to crash or run programs if it received specially
crafted network traffic.
It was discovered that gtk-vnc incorrectly validated certain data. A
malicious server could use this issue to cause gtk-vnc to crash, resulting
in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gtk-vnc: Integer overflow when processing SetColorMapEntries
vendor_redhat·2017-02-01·CVSS 9.8
CVE-2017-5885 [CRITICAL] CWE-190 gtk-vnc: Integer overflow when processing SetColorMapEntries
gtk-vnc: Integer overflow when processing SetColorMapEntries
Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.
An integer overflow flaw was found in gtk-vnc. A remote malicious VNC server could use this flaw to crash VNC viewers which are based on the gtk-vnc library.
Package: gtk-vnc (Red Hat Enterprise Linux 5) - Will not fix
Package: gtk-vnc (Red Hat Enterprise Linux 6) - Will not fix
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Will not fix
Debian
CVE-2017-5885: gtk-vnc - Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_...
vendor_debian·2017·CVSS 9.8
CVE-2017-5885 [CRITICAL] CVE-2017-5885: gtk-vnc - Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_...
Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.
Scope: local
bookworm: resolved (fixed in 0.6.0-3)
bullseye: resolved (fixed in 0.6.0-3)
forky: resolved (fixed in 0.6.0-3)
sid: resolved (fixed in 0.6.0-3)
trixie: resolved (fixed in 0.6.0-3)
GHSA
GHSA-m2p7-mwp9-g3w6: Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0
ghsa_unreviewed·2022-05-14
CVE-2017-5885 [CRITICAL] CWE-190 GHSA-m2p7-mwp9-g3w6: Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0
Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.
OSV
CVE-2017-5885: Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0
osv·2017-02-28·CVSS 9.8
CVE-2017-5885 [CRITICAL] CVE-2017-5885: Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0
Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5884 CVE-2017-5885 gtk-vnc: various flaws [fedora-all]
bugzilla·2017-02-03·CVSS 7.8
CVE-2017-5884 [HIGH] CVE-2017-5884 CVE-2017-5885 gtk-vnc: various flaws [fedora-all]
CVE-2017-5884 CVE-2017-5885 gtk-vnc: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While
Bugzilla
CVE-2017-5885 gtk-vnc: Integer overflow when processing SetColorMapEntries
bugzilla·2017-02-03·CVSS 9.8
CVE-2017-5885 [CRITICAL] CVE-2017-5885 gtk-vnc: Integer overflow when processing SetColorMapEntries
CVE-2017-5885 gtk-vnc: Integer overflow when processing SetColorMapEntries
It was found that vnc_connection_server_message() and vnc_color_map_set() functions do not check for integer overflow properly, leading to a malicious server being able to overwrite parts of the client memory, possibly leading to remote code execution under privileges of user running the VNC client.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=778050
Upstream patch:
https://git.gnome.org/browse/gtk-vnc/commit/?id=c8583fd3783c5b811590
Discussion:
Created gtk-vnc tracking bugs for this issue:
Affects: fedora-all [bug 1418955]
---
Created mingw-gtk-vnc tracking bugs for this issue:
Affects: fedora-all [bug 1418956]
---
CVE assignment:
http://openwall.com/lists/oss-security/2017/02/05/5
---
U
Bugzilla
CVE-2017-5884 CVE-2017-5885 mingw-gtk-vnc: various flaws [fedora-all]
bugzilla·2017-02-03·CVSS 7.8
CVE-2017-5884 [HIGH] CVE-2017-5884 CVE-2017-5885 mingw-gtk-vnc: various flaws [fedora-all]
CVE-2017-5884 CVE-2017-5885 mingw-gtk-vnc: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
http://www.openwall.com/lists/oss-security/2017/02/03/5http://www.openwall.com/lists/oss-security/2017/02/05/5http://www.securityfocus.com/bid/96016https://access.redhat.com/errata/RHSA-2017:2258https://bugzilla.gnome.org/show_bug.cgi?id=778050https://git.gnome.org/browse/gtk-vnc/commit/?id=c8583fd3783c5b811590fcb7bae4ce6e7344963ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LGPQ5MQR6SN4DYTEFACHP2PP5RR26KYK/http://www.openwall.com/lists/oss-security/2017/02/03/5http://www.openwall.com/lists/oss-security/2017/02/05/5http://www.securityfocus.com/bid/96016https://access.redhat.com/errata/RHSA-2017:2258https://bugzilla.gnome.org/show_bug.cgi?id=778050https://git.gnome.org/browse/gtk-vnc/commit/?id=c8583fd3783c5b811590fcb7bae4ce6e7344963ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LGPQ5MQR6SN4DYTEFACHP2PP5RR26KYK/
2017-02-28
Published