Heap-based Buffer Overflow in LibVNCClient Allows Remote Code Execution

Heap-based Buffer Overflow in LibVNCClient Allows Remote Code Execution

CVE-2016-9941 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Heap-based buffer overflow in rfbproto.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message containing a subrectangle outside of the client drawing area.

Learn more about our Cis Benchmark Audit For Server Software.