This application requires Javascript for optimal performance.

VNC.Server.ClientCutText.Message.Memory.Corruption

Release Date

Jun 24, 2010

Severity

high

Impact

System compromise: Remote attackers can gain control of vulnerable systems.
Denial of service

Description

This indicates an attack attempt against a memory-corruption vulnerability in RealVNC VNC Server.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted ClientCutText VNC command. It allows a remote attacker to execute arbitrary code.

Affected Products

RealVNC RealVNC 4.1.3

Recommended Actions

Upgrade to the latest versions:
http://www.realvnc.com/

Coverage

IPS
VCM

Reference/s

http://www.securityfocus.com/bid/39895 (BugTraq)

Reference: VID-23340