RealVNC 4.1.2 'vncviewer.exe' RFB Protocol Remote Code Execution Vulnerability
BID:33263
Info
RealVNC 4.1.2 'vncviewer.exe' RFB Protocol Remote Code Execution Vulnerability
| Bugtraq ID: | 33263 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4770 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2008 12:00AM |
| Updated: | Apr 13 2015 09:37PM |
| Credit: | Benjamin Bennett of the Pittsburgh Supercomputing Center |
| Vulnerable: |
Sun Solaris 10_x86 Sun Solaris 10_sparc Sun OpenSolaris build snv_96 Sun OpenSolaris build snv_95 Sun OpenSolaris build snv_92 Sun OpenSolaris build snv_91 Sun OpenSolaris build snv_90 Sun OpenSolaris build snv_89 Sun OpenSolaris build snv_88 Sun OpenSolaris build snv_87 Sun OpenSolaris build snv_85 Sun OpenSolaris build snv_84 Sun OpenSolaris build snv_83 Sun OpenSolaris build snv_82 Sun OpenSolaris build snv_80 Sun OpenSolaris build snv_78 Sun OpenSolaris build snv_104 Sun OpenSolaris build snv_103 Sun OpenSolaris build snv_102 Sun OpenSolaris build snv_101 Sun OpenSolaris build snv_100 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux Desktop version 4 Redhat Enterprise Linux 5 Server Redhat Desktop 3.0 RealVNC RealVNC Free Edition 4.1.2 RealVNC RealVNC 4.1.2 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service - CCSS7 0 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
RealVNC RealVNC Free Edition 4.1.3 RealVNC RealVNC 4.1.3 |
Discussion
RealVNC 4.1.2 'vncviewer.exe' RFB Protocol Remote Code Execution Vulnerability
RealVNC Viewer is prone to a remote code-execution vulnerability because it fails to adequately handle certain encoding types.
An attacker can exploit this issue to execute arbitrary code in the context of the vulnerable process. Failed exploit attempts are likely to result in denial-of-service conditions.
NOTE: This issue may be related to the vulnerability discussed in BID 30499 (RealVNC 4.1.2 'vncviewer.exe' Remote Denial of Service Vulnerability).
RealVNC 4.1.2 is vulnerable; earlier versions may also be affected.
RealVNC Viewer is prone to a remote code-execution vulnerability because it fails to adequately handle certain encoding types.
An attacker can exploit this issue to execute arbitrary code in the context of the vulnerable process. Failed exploit attempts are likely to result in denial-of-service conditions.
NOTE: This issue may be related to the vulnerability discussed in BID 30499 (RealVNC 4.1.2 'vncviewer.exe' Remote Denial of Service Vulnerability).
RealVNC 4.1.2 is vulnerable; earlier versions may also be affected.
Exploit / POC
RealVNC 4.1.2 'vncviewer.exe' RFB Protocol Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RealVNC 4.1.2 'vncviewer.exe' RFB Protocol Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 powerpc
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 hppa
Debian Linux 4.0 sparc
Debian Linux 4.0 s/390
Debian Linux 4.0 alpha
Debian Linux 4.0 mipsel
Debian Linux 4.0 ia-64
Debian Linux 4.0 mips
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 powerpc
-
Debian vnc4-common_4.1.1+X4.3.0-21+etch1_powerpc.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4-common_4.1.1+ X4.3.0-21+etch1_powerpc.deb -
Debian vnc4server_4.1.1+X4.3.0-21+etch1_powerpc.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4server_4.1.1+X 4.3.0-21+etch1_powerpc.deb -
Debian xvnc4viewer_4.1.1+X4.3.0-21+etch1_powerpc.deb
http://security.debian.org/pool/updates/main/v/vnc4/xvnc4viewer_4.1.1+ X4.3.0-21+etch1_powerpc.deb
Debian Linux 4.0 amd64
-
Debian vnc4-common_4.1.1+X4.3.0-21+etch1_amd64.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4-common_4.1.1+ X4.3.0-21+etch1_amd64.deb -
Debian vnc4server_4.1.1+X4.3.0-21+etch1_amd64.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4server_4.1.1+X 4.3.0-21+etch1_amd64.deb -
Debian xvnc4viewer_4.1.1+X4.3.0-21+etch1_amd64.deb
http://security.debian.org/pool/updates/main/v/vnc4/xvnc4viewer_4.1.1+ X4.3.0-21+etch1_amd64.deb
Debian Linux 4.0 ia-32
-
Debian vnc4-common_4.1.1+X4.3.0-21+etch1_i386.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4-common_4.1.1+ X4.3.0-21+etch1_i386.deb -
Debian vnc4server_4.1.1+X4.3.0-21+etch1_i386.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4server_4.1.1+X 4.3.0-21+etch1_i386.deb -
Debian xvnc4viewer_4.1.1+X4.3.0-21+etch1_i386.deb
http://security.debian.org/pool/updates/main/v/vnc4/xvnc4viewer_4.1.1+ X4.3.0-21+etch1_i386.deb
Debian Linux 4.0 hppa
-
Debian vnc4-common_4.1.1+X4.3.0-21+etch1_hppa.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4-common_4.1.1+ X4.3.0-21+etch1_hppa.deb -
Debian vnc4server_4.1.1+X4.3.0-21+etch1_hppa.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4server_4.1.1+X 4.3.0-21+etch1_hppa.deb -
Debian xvnc4viewer_4.1.1+X4.3.0-21+etch1_hppa.deb
http://security.debian.org/pool/updates/main/v/vnc4/xvnc4viewer_4.1.1+ X4.3.0-21+etch1_hppa.deb
Debian Linux 4.0 sparc
-
Debian vnc4-common_4.1.1+X4.3.0-21+etch1_sparc.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4-common_4.1.1+ X4.3.0-21+etch1_sparc.deb -
Debian vnc4server_4.1.1+X4.3.0-21+etch1_sparc.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4server_4.1.1+X 4.3.0-21+etch1_sparc.deb -
Debian xvnc4viewer_4.1.1+X4.3.0-21+etch1_sparc.deb
http://security.debian.org/pool/updates/main/v/vnc4/xvnc4viewer_4.1.1+ X4.3.0-21+etch1_sparc.deb
Debian Linux 4.0 s/390
-
Debian vnc4-common_4.1.1+X4.3.0-21+etch1_s390.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4-common_4.1.1+ X4.3.0-21+etch1_s390.deb -
Debian vnc4server_4.1.1+X4.3.0-21+etch1_s390.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4server_4.1.1+X 4.3.0-21+etch1_s390.deb -
Debian xvnc4viewer_4.1.1+X4.3.0-21+etch1_s390.deb
http://security.debian.org/pool/updates/main/v/vnc4/xvnc4viewer_4.1.1+ X4.3.0-21+etch1_s390.deb
Debian Linux 4.0 alpha
-
Debian vnc4-common_4.1.1+X4.3.0-21+etch1_alpha.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4-common_4.1.1+ X4.3.0-21+etch1_alpha.deb -
Debian vnc4server_4.1.1+X4.3.0-21+etch1_alpha.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4server_4.1.1+X 4.3.0-21+etch1_alpha.deb -
Debian xvnc4viewer_4.1.1+X4.3.0-21+etch1_alpha.deb
http://security.debian.org/pool/updates/main/v/vnc4/xvnc4viewer_4.1.1+ X4.3.0-21+etch1_alpha.deb
Debian Linux 4.0 mipsel
-
Debian vnc4-common_4.1.1+X4.3.0-21+etch1_mipsel.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4-common_4.1.1+ X4.3.0-21+etch1_mipsel.deb -
Debian vnc4server_4.1.1+X4.3.0-21+etch1_mipsel.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4server_4.1.1+X 4.3.0-21+etch1_mipsel.deb -
Debian xvnc4viewer_4.1.1+X4.3.0-21+etch1_mipsel.deb
http://security.debian.org/pool/updates/main/v/vnc4/xvnc4viewer_4.1.1+ X4.3.0-21+etch1_mipsel.deb
Debian Linux 4.0 ia-64
-
Debian vnc4-common_4.1.1+X4.3.0-21+etch1_ia64.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4-common_4.1.1+ X4.3.0-21+etch1_ia64.deb -
Debian vnc4server_4.1.1+X4.3.0-21+etch1_ia64.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4server_4.1.1+X 4.3.0-21+etch1_ia64.deb -
Debian xvnc4viewer_4.1.1+X4.3.0-21+etch1_ia64.deb
http://security.debian.org/pool/updates/main/v/vnc4/xvnc4viewer_4.1.1+ X4.3.0-21+etch1_ia64.deb
Debian Linux 4.0 mips
-
Debian vnc4-common_4.1.1+X4.3.0-21+etch1_mips.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4-common_4.1.1+ X4.3.0-21+etch1_mips.deb -
Debian vnc4server_4.1.1+X4.3.0-21+etch1_mips.deb
http://security.debian.org/pool/updates/main/v/vnc4/vnc4server_4.1.1+X 4.3.0-21+etch1_mips.deb -
Debian xvnc4viewer_4.1.1+X4.3.0-21+etch1_mips.deb
http://security.debian.org/pool/updates/main/v/vnc4/xvnc4viewer_4.1.1+ X4.3.0-21+etch1_mips.deb
References
RealVNC 4.1.2 'vncviewer.exe' RFB Protocol Remote Code Execution Vulnerability
References:
References: