CVE-2011-0904

Impact:
Low
Public Date:
2011-05-02
CWE:
CWE-125
Bugzilla:
694455: CVE-2011-0904 vino: Out of bounds read flaw by processing certain client raw encoding framebuffer update requests

The MITRE CVE dictionary describes this issue as:

The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when raw encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via a large (1) X position or (2) Y position value in a framebuffer update request that triggers an out-of-bounds memory access, related to the rfbTranslateNone and rfbSendRectEncodingRaw functions.

Find out more about CVE-2011-0904 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 3.5
Base Metrics AV:N/AC:M/Au:S/C:N/I:N/A:P
Access Vector Network
Access Complexity Medium
Authentication Single
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 6 (vino) RHSA-2013:0169 2013-01-21

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 6 kdenetwork Not affected
Red Hat Enterprise Linux 6 libvncserver Not affected
Red Hat Enterprise Linux 5 kdenetwork Will not fix
Red Hat Enterprise Linux 5 vino Will not fix
Red Hat Enterprise Linux 4 kdenetwork Will not fix
Red Hat Enterprise Linux 4 vino Will not fix

Mitigation

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.