LibVNCClient 是一个用于简化 VNC 客户端实现的库。在 0.9.12 至 0.9.15 版本中,恶意的(或处于中间人位置的)VNC 服务器可以迫使连接的 向其帧缓冲区(framebuffer)末尾之外写入由攻击者控制的数据。这是一种越界堆写入漏洞,攻击者可完全控制写入的长度、内容和偏移量。该漏洞无需身份验证(因为攻击者即为服务器端),在默认构建且使用默认配置的情况下即可生效,并且只需一个 消息,在受害者连接建立的瞬间即可触发。此漏洞会导致所有客户端无条件崩溃(拒绝服务);此外,我们在默认配置下还演示了
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| LibVNC | libvncserver | >= 0.9.12, <= 0.9.15 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| LibVNC | libvncserver | >= 0.9.12, <= 0.9.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet