VDB
GCVE-110-MAGEIA-2017-57
GCVE-110-MAGEIA-2017-57
Advisory Published
It was found that gtk-vnc code does not properly check boundaries of
subrectangle-containing tiles. A malicious server can use this to
overwrite parts of the client memory (CVE-2017-5884).
In addition, the vnc_connection_server_message() and vnc_color_map_set()
functions do not check for integer overflow properly, leading to a
malicious server being able to overwrite parts of the client memory
(CVE-2017-5885).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | mplayer | 0 (affected), 1.3.0-12.mga6 (unaffected), 0 (affected), 1.3.0-12.mga6.tainted (unaffected) | — |
| Mageia | gtk-vnc | 0 (affected), 0.5.3-6.1.mga5 (unaffected), 0 (affected), 0.5.3-6.1.mga5 (unaffected) | — |
Aliases
References
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.