LWN.net Logo

vnc: arbitrary code execution

Package(s):vnc CVE #(s):CVE-2008-4770
Created:January 27, 2009 Updated:March 9, 2009
Description: From the CVE entry: The CMsgReader::readRect function in the VNC Viewer component in RealVNC VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2, and Personal Edition P4.0 through P4.4.2 allows remote VNC servers to execute arbitrary code via crafted RFB protocol data, related to "encoding type."
Alerts:
Gentoo 200903-17 2009-03-09
CentOS CESA-2009:0261 2009-02-11
Red Hat RHSA-2009:0261-01 2009-02-11
Fedora FEDORA-2009-0991 2009-01-27
Debian DSA-1716-1 2009-01-31
Fedora FEDORA-2009-1001 2009-01-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds