UltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, which result in out-of-bound data being accessed by remote users. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.
The product does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ultravnc | Uvnc | * | 1.2.2.3 (excluding) |