ID |
CVE-2009-0388
|
Sažetak |
Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code via a large length value in a message, related to the (a) ClientConnection::CheckBufferSize and (b) ClientConnection::CheckFileZipBufferSize functions in ClientConnection.cpp. |
Reference |
|
CVSS |
Base: | 10.0 |
Impact: | 10.0 |
Exploitability: | 10.0 |
|
Pristup |
Vektor | Složenost | Autentikacija |
NETWORK |
LOW |
NONE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
COMPLETE |
COMPLETE |
COMPLETE |
|
CVSS vektor |
AV:N/AC:L/Au:N/C:C/I:C/A:C |
Zadnje važnije ažuriranje |
11-10-2018 - 21:01 |
Objavljeno |
04-02-2009 - 19:30 |