Files
CVEs-PoC/2016/CVE-2016-9942.md
2025-09-29 21:09:30 +02:00

878 B

CVE-2016-9942

Description

Heap-based buffer overflow in ultra.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message with the Ultra type tile, such that the LZO payload decompressed length exceeds what is specified by the tile dimensions.

POC

Reference

Github