CVE Vulnerabilities

CVE-2017-5884

Incorrect Access of Indexable Resource ('Range Error')

Published: Feb 28, 2017 | Modified: Feb 12, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
3.1 LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM

gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.

Weakness

The product does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed using an index or pointer, such as memory or files.

Affected Software

Name Vendor Start Version End Version
Fedora Fedoraproject 25 (including) 25 (including)
Red Hat Enterprise Linux 7 RedHat gtk-vnc-0:0.7.0-2.el7 *
Gtk-vnc Ubuntu precise *
Gtk-vnc Ubuntu trusty *
Gtk-vnc Ubuntu upstream *
Gtk-vnc Ubuntu xenial *
Gtk-vnc Ubuntu yakkety *

References