Security Advisory

CVE-2019-15694

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-12-26 14:59:01
Last updated 2024-08-05 00:56:22
Assigner Kaspersky
State PUBLISHED

Description

TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which could be triggered from DecodeManager::decodeRect. Vulnerability occurs due to the signdness error in processing MemOutStream. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity.