← Retour aux CVEs
CVE-2019-15683
CRITICAL9.8
Description
TurboVNC server code contains stack buffer overflow vulnerability in commit prior to cea98166008301e614e0d36776bf9435a536136e. This could possibly result into remote code execution, since stack frame is not protected with stack canary. This attack appear to be exploitable via network connectivity. To exploit this vulnerability authorization on server is required. These issues have been fixed in commit cea98166008301e614e0d36776bf9435a536136e.
Details CVE
Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie10/29/2019
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
turbovnc:turbovnc
Faiblesses (CWE)
CWE-121CWE-787
References
https://github.com/TurboVNC/turbovnc/commit/cea98166008301e614e0d36776bf9435a536136e(vulnerability@kaspersky.com)
https://github.com/TurboVNC/turbovnc/commit/cea98166008301e614e0d36776bf9435a536136e(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.