An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-02-19T15:00:00

Updated: 2020-10-23T12:06:23

Reserved: 2018-02-19T00:00:00


Link: CVE-2018-7225

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-02-19T15:29:00.253

Modified: 2020-10-23T13:15:15.437


Link: CVE-2018-7225

JSON object: View

cve-icon Redhat Information

No data.

CWE