Vulnerability Note VU#721460
UltraVNC buffer overflow vulnerability
Overview
UltraVNC viewer contains a buffer overflow vulnerability. If exploited, this vulnerability may allow an attacker to execute arbitrary code.
Description
UltraVNC viewer is a remote desktop application that allows a user to control compatible VNC servers. The UltraVNC viewer includes a listen mode that accepts connections from remote hosts. The UltraVNC viewer contains a buffer overflow vulnerability. This vulnerability may be triggered by sending a malformed packet during the protocol negotiation phase of a VNC session. |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code. |
Solution
Upgrade |
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| UltraVNC | Affected | 04 Mar 2008 | 15 Mar 2008 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://forum.ultravnc.info/viewtopic.php?t=11850
- http://forum.ultravnc.info/viewtopic.php?p=43529
- http://secunia.com/advisories/28747/
- http://www.microsoft.com/technet/security/smallbusiness/prodtech/windowsxp/cfgfwall.mspx
- http://technet2.microsoft.com/WindowsVista/en/library/19b429b3-c32b-4cbd-ae2a-8e77f2ced35c1033.mspx?mfr=true
- http://forum.ultravnc.info/viewtopic.php?t=6005&highlight=5400
Credit
Thanks to the UltraVNC team and Secunia for information that was used in this report.
This document was written by Ryan Giobbi.
Other Information
- CVE IDs: CVE-2008-0610
- Date Public: 01 Feb 2008
- Date First Published: 15 Mar 2008
- Date Last Updated: 16 Mar 2008
- Severity Metric: 12.86
- Document Revision: 31
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.