An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-02-19T15:00:00

Updated: 2024-08-05T06:24:11.789Z

Reserved: 2018-02-19T00:00:00

Link: CVE-2018-7225

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-02-19T15:29:00.253

Modified: 2020-10-23T13:15:15.437

Link: CVE-2018-7225

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-02-18T00:00:00Z

Links: CVE-2018-7225 - Bugzilla