CVE Vulnerabilities

CVE-2009-0388

Published: Feb 04, 2009 | Modified: Oct 11, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code via a large length value in a message, related to the (a) ClientConnection::CheckBufferSize and (b) ClientConnection::CheckFileZipBufferSize functions in ClientConnection.cpp.

Affected Software

Name Vendor Start Version End Version
Tightvnc Tightvnc 1.3.9 (including) 1.3.9 (including)
Ultravnc Ultravnc 1.0.2 (including) 1.0.2 (including)
Ultravnc Ultravnc 1.0.5 (including) 1.0.5 (including)

References