We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.
Reserved 2019-08-27 | Published 2025-01-24 | Updated 2025-01-24 | Assigner KasperskyCWE-122: Heap-based Buffer Overflow
2020-03-23: | Advisory published by Kaspersky |
Pavel Cheremushkin from Kaspersky
ics-cert.kaspersky.com/...on-libvnc-version-prior-to-0-9-12/ (KLCERT-20-009: Remote Code Execution on LibVNC version prior to 0.9.12)
Support options