gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2017-02-28T18:00:00
Updated: 2024-08-05T15:11:48.753Z
Reserved: 2017-02-04T00:00:00
Link: CVE-2017-5884
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-02-28T18:59:00.407
Modified: 2024-11-21T03:28:36.567
Link: CVE-2017-5884
Redhat