The CMsgReader::readRect function in the VNC Viewer component in RealVNC...
Vulnerability Description
The CMsgReader::readRect function in the VNC Viewer component in RealVNC VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2, and Personal Edition P4.0 through P4.4.2 allows remote VNC servers to execute arbitrary code via crafted RFB protocol data, related to "encoding type."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-4770
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.gentoo.org/security/en/glsa/glsa-200903-17.xml
- http://www.realvnc.com/products/upgrade.html
- https://www.redhat.com/archives/fedora-package-announce/2009-January/msg01025.html
- http://www.realvnc.com/products/free/4.1/release-notes.html
- http://secunia.com/advisories/33689
- http://secunia.com/advisories/34184
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-140455-01-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-248526-1
- http://www.securityfocus.com/bid/31832
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45969
- http://www.securityfocus.com/bid/33263
- http://secunia.com/advisories/32317
- http://www.vupen.com/english/advisories/2008/2868
- http://www.realvnc.com/pipermail/vnc-list/2008-November/059432.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47937
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9367
- http://www.redhat.com/support/errata/RHSA-2009-0261.html
More from realvnc
View All →Affected Vendor
realvnc
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.