Vulnerability Details CVE-2017-5884
gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.2%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.8
Products affected by CVE-2017-5884
-
cpe:2.3:a:gnome:gtk-vnc:-
-
cpe:2.3:a:gnome:gtk-vnc:0.1.0
-
cpe:2.3:a:gnome:gtk-vnc:0.2.0
-
cpe:2.3:a:gnome:gtk-vnc:0.3.7
-
cpe:2.3:a:gnome:gtk-vnc:0.3.8
-
cpe:2.3:a:gnome:gtk-vnc:0.4.2
-
cpe:2.3:a:gnome:gtk-vnc:0.5.1
-
cpe:2.3:a:gnome:gtk-vnc:0.5.2
-
cpe:2.3:a:gnome:gtk-vnc:0.5.3
-
cpe:2.3:a:gnome:gtk-vnc:0.5.4
-
cpe:2.3:a:gnome:gtk-vnc:0.6.0
-
cpe:2.3:o:fedoraproject:fedora:25