CVE-2008-4770
Summary
| CVE | CVE-2008-4770 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-01-16 21:30:03 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The CMsgReader::readRect function in the VNC Viewer component in RealVNC VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2, and Personal Edition P4.0 through P4.4.2 allows remote VNC servers to execute arbitrary code via crafted RFB protocol data, related to "encoding type." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Realvnc | Realvnc | 4.0 | All | free | All |
| Application | Realvnc | Realvnc | 4.1.2 | All | free | All |
| Application | Realvnc | Realvnc | 4.4.2 | All | enterprise | All |
| Application | Realvnc | Realvnc | e4.0 | All | enterprise | All |
| Application | Realvnc | Realvnc | p4.0 | All | personal | All |
| Application | Realvnc | Realvnc | p4.4.2 | All | personal | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VNC Viewer Vulnerability CVE-2008-4770 | af854a3a-2127-422b-91ae-364da2661108 | www.realvnc.com | |
| RealVNC 4.1.2 'CMsgReader::readRect()' Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Gentoo update for vnc - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| RealVNC - VNC® Viewer Vulnerability CVE-2008-4770 | af854a3a-2127-422b-91ae-364da2661108 | www.realvnc.com | Vendor Advisory |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Vendor Advisory |
| RealVNC 4.1.2 'vncviewer.exe' RFB Protocol Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| RealVNC - VNC Free Edition 4.1 - release notes | af854a3a-2127-422b-91ae-364da2661108 | www.realvnc.com | |
| Fedora update for vnc - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| [SECURITY] Fedora 9 Update: vnc-4.1.3-1.fc9 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| RealVNC VNC Viewer "CMsgReader::readRect()" Encoding Type Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo Linux Documentation -- Real VNC: User-assisted execution of arbitrary code | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.