openSUSE-SU-2020:0087Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00039.html CVE-2019-15693
HIGH
Record summary
CVE-2019-15693 has a selected CVSS score of 7.2 (high).
Description
TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which occurs in TightDecoder::FilterGradient. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
TigerVNCBrowse Kaspersky / TigerVNC | CVE List | 1.10.0 | affected |
References
5github.com
https://github.com/CendioOssman/tigervnc/commit/b4ada8d0c6dac98c8b91fc64d112569a8ae5fb95 github.com
https://github.com/TigerVNC/tigervnc/releases/tag/v1.10.1 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-15693 [oss-security] 20191220 VNC vulnerabilities. TigerVNC security updatemailing list
https://www.openwall.com/lists/oss-security/2019/12/20/2