CVE
- Id
- 96762
- CVE No.
- CVE-2016-9942
- Status
- Candidate
- Description
- Heap-based buffer overflow in ultra.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message with the Ultra type tile, such that the LZO payload decompressed length exceeds what is specified by the tile dimensions.
- Phase
- Assigned (20161213)
- Votes
- None (candidate not yet proposed)
- Comments