An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-02-19T15:00:00
Updated: 2024-08-05T06:24:11.789Z
Reserved: 2018-02-19T00:00:00
Link: CVE-2018-7225
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-02-19T15:29:00.253
Modified: 2024-11-21T04:11:49.250
Link: CVE-2018-7225
Redhat