Core Security Technologies Advisory...

- AV AC AU C I A
发布: 2008-12-09
修订: 2025-04-13

Core Security Technologies Advisory - Vinagre is a VNC client for the GNOME Desktop. A format string error has been found on the 'vinagre_utils_show_error()' function that can be exploited via commands issued from a malicious server containing format string specifiers on the VNC name. In a web based attack scenario, the user would be required to connect to a malicious server. Successful exploitation would then allow the attacker to execute arbitrary code with the privileges of the Vinagre user. Proof of concept code included.Versions 2.24.1 and below are affected.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息