Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-5885

Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.6%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
References
Products affected by CVE-2017-5885
  • Gnome » Gtk-Vnc » Version: N/A
    cpe:2.3:a:gnome:gtk-vnc:-
  • Gnome » Gtk-Vnc » Version: 0.1.0
    cpe:2.3:a:gnome:gtk-vnc:0.1.0
  • Gnome » Gtk-Vnc » Version: 0.2.0
    cpe:2.3:a:gnome:gtk-vnc:0.2.0
  • Gnome » Gtk-Vnc » Version: 0.3.7
    cpe:2.3:a:gnome:gtk-vnc:0.3.7
  • Gnome » Gtk-Vnc » Version: 0.3.8
    cpe:2.3:a:gnome:gtk-vnc:0.3.8
  • Gnome » Gtk-Vnc » Version: 0.4.2
    cpe:2.3:a:gnome:gtk-vnc:0.4.2
  • Gnome » Gtk-Vnc » Version: 0.5.1
    cpe:2.3:a:gnome:gtk-vnc:0.5.1
  • Gnome » Gtk-Vnc » Version: 0.5.2
    cpe:2.3:a:gnome:gtk-vnc:0.5.2
  • Gnome » Gtk-Vnc » Version: 0.5.3
    cpe:2.3:a:gnome:gtk-vnc:0.5.3
  • Gnome » Gtk-Vnc » Version: 0.5.4
    cpe:2.3:a:gnome:gtk-vnc:0.5.4
  • Gnome » Gtk-Vnc » Version: 0.6.0
    cpe:2.3:a:gnome:gtk-vnc:0.6.0
  • Fedoraproject » Fedora » Version: 25
    cpe:2.3:o:fedoraproject:fedora:25


Contact Us

Shodan ® - All rights reserved