VNC: TightVNC vncviewer rfbServerCutText Handler Integer Overflow

This signature detects attempts to exploit a known vulnerability against TightVNC. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via network connectivity.

Affected Products

Tightvnc tightvnc

Short Name
VNC:OVERFLOW:TIGHT-VNC-VW
Severity
Major
Recommended
False
Recommended Action
Drop
Category
VNC
Keywords
CVE-2019-15678 Handler Integer Overflow TightVNC rfbServerCutText vncviewer
Release Date
05/31/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3710
False Positive
Unknown
Vendors

Tightvnc

Found a potential security threat?