QID 376156
Date Published: 2021-12-14
QID 376156: TightVNC Buffer Overflow Vulnerability
In computing, TightVNC is a free and open-source remote desktop software server and client application for Linux and Windows
Buffer Overflow vulnerability in tvnviewer.exe of TightVNC Viewer allows a remote attacker to execute arbitrary instructions via a crafted FramebufferUpdate packet from a VNC server.
Affected Software:
TightVNC version upto 2.8.59.0
QID Detection Logic (Authenticated):
This checks for vulnerable version of TightVNC by checking the .exe version
Allows a remote attacker to execute arbitrary instructions via a crafted FramebufferUpdate packet from a VNC server
Solution
Upgrade to TightVNC Refer to TightVNC
Vendor References
- TightVNC -
www.tightvnc.com/whatsnew.php
CVEs related to QID 376156
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| TightVNC |
|