CVE-2019-8273
Summary
| CVE | CVE-2019-8273 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-08 23:29:00 UTC |
| Updated | 2020-10-22 16:58:00 UTC |
| Description | UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer request handler, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1212. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| cert-portal.siemens.com/productcert/pdf/ssa-927095.pdf |
CONFIRM |
cert-portal.siemens.com |
Third Party Advisory |
| Siemens SINUMERIK | CISA |
MISC |
www.us-cert.gov |
Third Party Advisory, US Government Resource |
| KLCERT-19-020: UltraVNC Heap-based Buffer Overflow | Kaspersky ICS CERT |
MISC |
ics-cert.kaspersky.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590854 Schneider Electric TelevisGo Multiple Vulnerabilities (SEVD-2019-225-05)