CVE-2019-15694

Published
View on NVD ↗
CVSS v3
7.2
HIGH
CVSS v2
6.5
MEDIUM
Affected
2
PROJECTS

Description

TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which could be triggered from DecodeManager::decodeRect. Vulnerability occurs due to the signdness error in processing MemOutStream. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity.

High performance, multi-platform VNC client and server
GitHubGitHub
7.18K