Description
Heap-based buffer overflow in rfbproto.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message containing a subrectangle outside of the client drawing area.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-777-1 | libvncserver security update |
Debian DLA |
DLA-1979-1 | italc security update |
Debian DSA |
DSA-3753-1 | libvncserver security update |
EUVD |
EUVD-2016-10728 | Heap-based buffer overflow in rfbproto.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message containing a subrectangle outside of the client drawing area. |
Ubuntu USN |
USN-3171-1 | LibVNCServer vulnerabilities |
Ubuntu USN |
USN-4587-1 | iTALC vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T03:07:31.407Z
Reserved: 2016-12-13T00:00:00.000Z
Link: CVE-2016-9941
No data.
Status : Modified
Published: 2016-12-31T18:59:00.133
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-9941
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN