Back

CRITICAL

libvncserver: HandleCursorShape() integer overflow resulting in heap-based buffer overflow

Published Jan 24, 2025

Description

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

Affected products

Remediation

Vendor solution

Update LibVNCServer to the commit with hash 54220248886b5001fbbb9fa73c4e1a2cb9413fed or newer.

Red Hat mitigation

Libvncserver should not be used to connect to untrusted server.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Kaspersky
Published Jan 24, 2025
Updated Jan 24, 2025
Reserved Aug 27, 2019
CISA Vulnrichment
Updated Jan 24, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 20, 2019