{ "id": "CVE-2011-0904", "sourceIdentifier": "cve@mitre.org", "published": "2011-05-10T18:55:01.263", "lastModified": "2017-08-17T01:33:45.133", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when raw encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via a large (1) X position or (2) Y position value in a framebuffer update request that triggers an out-of-bounds memory access, related to the rfbTranslateNone and rfbSendRectEncodingRaw functions." }, { "lang": "es", "value": "La funci\u00f3n rfbSendFramebufferUpdate en server/libvncserver/rfbserver.c en vino-server en Vino v2.x antes de v2.28.3, v2.32.x antes de v2.32.2, v3.0.x antes de v3.0.2, y v3.1.x antes de v3.1.1, cuando se utiliza la codificaci\u00f3n \"raw\", permite a usuarios autenticados remotamente causar una denegaci\u00f3n de servicio (ca\u00edda del demonio) a trav\u00e9s de un gran tama\u00f1o en el valor de (1) la posici\u00f3n X o (2) la posici\u00f3n Y en una solicitud de actualizaci\u00f3n de uso de este dispositivo que provoca un acceso a memoria fuera de l\u00edmites, relacionado con las funciones rfbTranslateNone y rfbSendRectEncodingRaw." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:S/C:N/I:N/A:P", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "SINGLE", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 3.5 }, "baseSeverity": "LOW", "exploitabilityScore": 6.8, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-119" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.7:*:*:*:*:*:*:*", "matchCriteriaId": "41927755-3E1C-4177-8977-F52B38F3E053" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.7.3:*:*:*:*:*:*:*", "matchCriteriaId": "6C4B1AEB-B4BA-4215-9F2C-1700CD3111E7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.7.3.1:*:*:*:*:*:*:*", "matchCriteriaId": "FF482208-D0E6-457E-953F-6E2361350565" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.7.4:*:*:*:*:*:*:*", "matchCriteriaId": "552A7EEF-1909-4A23-98EF-81DF362C2248" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.7.4.90:*:*:*:*:*:*:*", "matchCriteriaId": "2C62B9DA-E24F-4558-8B72-0C95A45A37BF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.7.4.91:*:*:*:*:*:*:*", "matchCriteriaId": "543D8E9D-70D7-436B-9BDC-8A826A2299C3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.7.92:*:*:*:*:*:*:*", "matchCriteriaId": "650B8890-EB29-4724-844F-4A32E050D08F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.8:*:*:*:*:*:*:*", "matchCriteriaId": "730B2130-FB0E-48BA-B34A-C903ED08D76E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.9:*:*:*:*:*:*:*", "matchCriteriaId": "5337B18C-36F9-407F-B877-89D3D9F9B1BC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.9.2:*:*:*:*:*:*:*", "matchCriteriaId": "E865590A-9C6D-44BE-A06F-C2EB89843654" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.10:*:*:*:*:*:*:*", "matchCriteriaId": "A04843B1-63EE-4A23-97C1-AB1E107EB7F5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.11:*:*:*:*:*:*:*", "matchCriteriaId": "9764CB5E-B515-4996-AFDE-C0498F7E9008" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.12:*:*:*:*:*:*:*", "matchCriteriaId": "31133388-2D96-4524-99AD-AA68BA77241B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.13:*:*:*:*:*:*:*", "matchCriteriaId": "38EC1414-090D-4C68-87A7-27B008368EBA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.13.5:*:*:*:*:*:*:*", "matchCriteriaId": "34F405B9-E543-40DB-8421-D529615FE3EA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.14:*:*:*:*:*:*:*", "matchCriteriaId": "DF93A176-DE41-4E97-9811-23C6D2E3FA4C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.15:*:*:*:*:*:*:*", "matchCriteriaId": "00576CED-5848-4BD6-B243-47BC53DDAF97" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.16:*:*:*:*:*:*:*", "matchCriteriaId": "9F8F2CFF-1100-4F39-8081-04CDEAFA0A4E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.17:*:*:*:*:*:*:*", "matchCriteriaId": "F3B76C84-3BB3-4698-A65F-66DDF1EA7D80" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.17.2:*:*:*:*:*:*:*", "matchCriteriaId": "EF372DB5-2DC8-4D51-8238-91259B8F6DAA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.17.4:*:*:*:*:*:*:*", "matchCriteriaId": "7AD934ED-727D-4F76-BEFB-8BC6289E6C31" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.17.5:*:*:*:*:*:*:*", "matchCriteriaId": "CE80D282-639F-4B3B-917F-78C9E2DE9ACA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.17.92:*:*:*:*:*:*:*", "matchCriteriaId": "477A4038-A94F-4D67-94A5-9AF755164B83" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.18:*:*:*:*:*:*:*", "matchCriteriaId": "F9ABA30A-CCEB-452C-8CDF-71BF8BA54328" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.18.1:*:*:*:*:*:*:*", "matchCriteriaId": "618D194C-D298-4C09-9F60-35719011B7CA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.19:*:*:*:*:*:*:*", "matchCriteriaId": "4D61AFC5-B296-45C8-8032-DAAA77FF8B4A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.19.5:*:*:*:*:*:*:*", "matchCriteriaId": "7914FF1F-E098-4359-A90E-6317648139C7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.19.90:*:*:*:*:*:*:*", "matchCriteriaId": "7549E435-4C0B-461D-811F-7291540E28D1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.19.92:*:*:*:*:*:*:*", "matchCriteriaId": "77F69530-C2BF-4EC5-A0B1-305C1EF734EC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.20:*:*:*:*:*:*:*", "matchCriteriaId": "518CBBF2-0F03-4700-A571-3F1FC7A36E8A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.20.1:*:*:*:*:*:*:*", "matchCriteriaId": "6D9200DB-5A3A-458D-A57E-176A6243ADDB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.21:*:*:*:*:*:*:*", "matchCriteriaId": "B163B52F-7A94-4F7C-873D-61F031043701" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.21.1:*:*:*:*:*:*:*", "matchCriteriaId": "823D1043-98CF-4406-AEA0-988A3139E753" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.21.2:*:*:*:*:*:*:*", "matchCriteriaId": "5FEE04E0-8E35-4A20-972F-28AAEA033C70" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.21.3:*:*:*:*:*:*:*", "matchCriteriaId": "8ADDF708-0EC8-473A-9FA3-F94EE8939D08" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.21.90:*:*:*:*:*:*:*", "matchCriteriaId": "E6F65CD5-2ED0-4BFE-B267-04908843B752" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.21.91:*:*:*:*:*:*:*", "matchCriteriaId": "8F2DD4B9-322D-4D05-A3E6-56BBA8C732F5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.21.92:*:*:*:*:*:*:*", "matchCriteriaId": "D5FFA5A6-5378-45CB-9360-FFEAC67DCCA5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.22:*:*:*:*:*:*:*", "matchCriteriaId": "E18BEF6E-3749-4E7E-8A34-F6577204BC28" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.22.1:*:*:*:*:*:*:*", "matchCriteriaId": "E077DC55-D51B-4408-9746-FA88DCA39938" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.22.2:*:*:*:*:*:*:*", "matchCriteriaId": "9C0DAA31-709E-40D0-805C-01FE87CDCD26" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.23:*:*:*:*:*:*:*", "matchCriteriaId": "C1772115-C603-4A11-8489-321120B8A1B5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.23.5:*:*:*:*:*:*:*", "matchCriteriaId": "859A4E2E-BD8E-4787-8E10-DA420F4193BA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.23.90:*:*:*:*:*:*:*", "matchCriteriaId": "986576AE-C3B3-4161-BEDF-4CC9584EACC5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.23.91:*:*:*:*:*:*:*", "matchCriteriaId": "D9FCD3F9-AB94-4DD5-B6D0-CB8C66091134" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.23.92:*:*:*:*:*:*:*", "matchCriteriaId": "E0F07686-3E95-43DA-AD01-90E33D71AB66" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.24:*:*:*:*:*:*:*", "matchCriteriaId": "DC2CDDB3-ADFD-4B83-94ED-CB2A632956F2" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.24.1:*:*:*:*:*:*:*", "matchCriteriaId": "9107C16B-47A2-4906-BC07-F1FC869AFA3C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.25:*:*:*:*:*:*:*", "matchCriteriaId": "2973DE8A-A346-44B5-B56D-EC33115FC548" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.25.3:*:*:*:*:*:*:*", "matchCriteriaId": "B854925C-5F29-491D-AC8B-87EC53EA2ABE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.25.4:*:*:*:*:*:*:*", "matchCriteriaId": "87C4C344-2028-453A-B66A-D7AE46C01C94" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.25.5:*:*:*:*:*:*:*", "matchCriteriaId": "7310615E-BDC8-48D5-A8E4-53808E67AA76" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.25.90:*:*:*:*:*:*:*", "matchCriteriaId": "1A60F4AC-7C1D-4FD3-A4AF-872082093609" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.25.91:*:*:*:*:*:*:*", "matchCriteriaId": "C5AA78F1-5331-4782-B158-CE1CEA929429" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.25.92:*:*:*:*:*:*:*", "matchCriteriaId": "2E41EDE1-BCA4-4E2F-B655-DFF040DDABCA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.26:*:*:*:*:*:*:*", "matchCriteriaId": "42F6A115-01FB-4F44-880A-60DFEBFD7504" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.26.1:*:*:*:*:*:*:*", "matchCriteriaId": "D9C9856E-B1E6-4E36-9758-8CFA9ADD9303" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.26.2:*:*:*:*:*:*:*", "matchCriteriaId": "3C762D77-E35F-4F0F-BAB3-D325D769DBA1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.27:*:*:*:*:*:*:*", "matchCriteriaId": "4DBA2BE3-439E-4F5F-9AFE-F02BE8882F9F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.27.5:*:*:*:*:*:*:*", "matchCriteriaId": "8037FB93-8B30-4AFA-A391-2110D40CFF62" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.27.90:*:*:*:*:*:*:*", "matchCriteriaId": "CCC199D2-B527-484A-9215-6490952E1865" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.27.91:*:*:*:*:*:*:*", "matchCriteriaId": "929A2439-2644-4F92-9873-A2D1041C6C4E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.27.92:*:*:*:*:*:*:*", "matchCriteriaId": "972490D5-7AF3-4EB2-B6C1-8A9C66F6889E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.28:*:*:*:*:*:*:*", "matchCriteriaId": "71E9E6F4-FF60-4DDB-9F65-10D0B973E633" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.28.1:*:*:*:*:*:*:*", "matchCriteriaId": "7AE96879-862B-4D72-9194-9278B88D3B9E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.28.2:*:*:*:*:*:*:*", "matchCriteriaId": "936EAF0C-141D-4DC1-92AD-EA4D34EEC2D5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.32.0:*:*:*:*:*:*:*", "matchCriteriaId": "65FE82D9-9B70-4D30-B64A-DAE742734719" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:2.32.1:*:*:*:*:*:*:*", "matchCriteriaId": "8DBD543C-19C0-4AF2-9E87-28758BD865D1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:3.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "2CBD087C-2AEC-4343-BD74-0F35C7BAD35A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:3.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "8EE1E16E-9022-4B32-A726-9184BE99A323" }, { "vulnerable": true, "criteria": "cpe:2.3:a:david_king:vino:3.1:*:*:*:*:*:*:*", "matchCriteriaId": "B47D886F-F6D1-46F4-8E91-8EBA00D43505" } ] } ] } ], "references": [ { "url": "http://ftp.gnome.org/pub/GNOME/sources/vino/2.28/vino-2.28.3.news", "source": "cve@mitre.org" }, { "url": "http://ftp.gnome.org/pub/GNOME/sources/vino/2.32/vino-2.32.2.news", "source": "cve@mitre.org" }, { "url": "http://ftp.gnome.org/pub/GNOME/sources/vino/3.0/vino-3.0.2.news", "source": "cve@mitre.org" }, { "url": "http://git.gnome.org/browse/vino/commit/?id=0c2c9175963fc56bf2af10e42867181332f96ce0", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "http://git.gnome.org/browse/vino/commit/?id=456dadbb5c5971d3448763a44c05b9ad033e522f", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "http://git.gnome.org/browse/vino/commit/?id=8beefcf7792d343c10c919ee0c928c81f73b1279", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "http://git.gnome.org/browse/vino/commit/?id=d050a22b1c284b633c407ef92fde95c47e8fdb8a", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "http://git.gnome.org/browse/vino/commit/?id=dff52694a384fe95195f2211254026b752d63ec4", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "http://git.gnome.org/browse/vino/commit/?id=e17bd4e369f90748654e31a4867211dc7610975d", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "http://git.gnome.org/browse/vino/log/?h=gnome-2-30", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "http://git.gnome.org/browse/vino/tree/NEWS", "source": "cve@mitre.org" }, { "url": "http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html", "source": "cve@mitre.org" }, { "url": "http://rhn.redhat.com/errata/RHSA-2013-0169.html", "source": "cve@mitre.org" }, { "url": "http://www.debian.org/security/2011/dsa-2238", "source": "cve@mitre.org" }, { "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2011:087", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/47681", "source": "cve@mitre.org" }, { "url": "http://www.ubuntu.com/usn/usn-1128-1/", "source": "cve@mitre.org" }, { "url": "http://www.vupen.com/english/advisories/2011/1144", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "https://bugzilla.gnome.org/show_bug.cgi?id=641802", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "https://bugzilla.redhat.com/show_bug.cgi?id=694455", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67243", "source": "cve@mitre.org" } ] }