CVE Database
/

CVE-2009-0388

Back to search

CVE-2009-0388

Published: Feb 4, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code via a large length value in a message, related to the (a) ClientConnection::CheckBufferSize and (b) ClientConnection::CheckFileZipBufferSize functions in ClientConnection.cpp.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2009-0321
vdb-entry
x_refsource_VUPEN
33568
vdb-entry
x_refsource_BID
8024
exploit
x_refsource_EXPLOIT-DB
ADV-2009-0322
vdb-entry
x_refsource_VUPEN
7990
exploit
x_refsource_EXPLOIT-DB
33807
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now