Stack Buffer Overflow in UltraVNC by UltraVNC Team
CVE-2019-8276
7.5HIGH
Summary
UltraVNC revision 1211 contains a stack buffer overflow vulnerability within the VNC server code, specifically in the file transfer request handler. Exploitation of this vulnerability can lead to Denial of Service (DoS) attacks, where the server may become unresponsive. The vulnerability can be triggered through network connectivity, highlighting the importance of securing network interfaces. This issue has been addressed and resolved in revision 1212.
Affected Version(s)
UltraVNC 1.2.2.3
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved