CVE-2019-15693

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
26/12/2019
Last modified:
20/01/2023

Description

TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which occurs in TightDecoder::FilterGradient. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tigervnc:tigervnc:*:*:*:*:*:*:*:* 1.10.1 (excluding)