LibVNCServer 0.9.12 release and earlier contains heap...
High severity
Unreviewed
Published
Jan 24, 2025
to the GitHub Advisory Database
•
Updated Jan 24, 2025
Description
Published by the National Vulnerability Database
Jan 24, 2025
Published to the GitHub Advisory Database
Jan 24, 2025
Last updated
Jan 24, 2025
LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.
References