CVE-2017-5885
gtk-vnc: Integer overflow when processing SetColorMapEntries
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.
Múltiples desbordamientos de entero en las funciones (1) vnc_connection_server_message y (2) vnc_color_map_set en gtk-vnc en versiones anteriores a 0.7.0 permiten a servidores remotos provocar una denegación de servicio (caída) o la posibilidad de ejecutar código arbitrario a través de vectores implicando SetColorMapEntries, lo que desencadena un desbordamiento de búfer.
An integer overflow flaw was found in gtk-vnc. A remote malicious VNC server could use this flaw to crash VNC viewers which are based on the gtk-vnc library.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-02-04 CVE Reserved
- 2017-02-20 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-190: Integer Overflow or Wraparound
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2017/02/03/5 | Mailing List | |
http://www.openwall.com/lists/oss-security/2017/02/05/5 | Mailing List | |
http://www.securityfocus.com/bid/96016 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://bugzilla.gnome.org/show_bug.cgi?id=778050 | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://git.gnome.org/browse/gtk-vnc/commit/?id=c8583fd3783c5b811590fcb7bae4ce6e7344963e | 2023-02-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 25 Search vendor "Fedoraproject" for product "Fedora" and version "25" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Gtk-vnc Search vendor "Gnome" for product "Gtk-vnc" | <= 0.6.0 Search vendor "Gnome" for product "Gtk-vnc" and version " <= 0.6.0" | - |
Affected
|