Critical severity9.8NVD Advisory· Published Dec 31, 2016· Updated May 6, 2026
CVE-2016-9942
CVE-2016-9942
Description
Heap-based buffer overflow in ultra.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message with the Ultra type tile, such that the LZO payload decompressed length exceeds what is specified by the tile dimensions.
Affected products
1- cpe:2.3:a:libvncserver_project:libvncserver:0.9.10:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.debian.org/security/2017/dsa-3753nvd
- www.securityfocus.com/bid/95170nvd
- github.com/LibVNC/libvncserver/pull/137nvd
- github.com/LibVNC/libvncserver/releases/tag/LibVNCServer-0.9.11nvd
- lists.debian.org/debian-lts-announce/2019/10/msg00042.htmlnvd
- security.gentoo.org/glsa/201702-24nvd
- usn.ubuntu.com/4587-1/nvd
News mentions
0No linked articles in our index yet.