Critical severity9.8NVD Advisory· Published Feb 28, 2017· Updated May 13, 2026
CVE-2017-5581
CVE-2017-5581
Description
Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE message with subrectangle outside framebuffer boundaries.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.openwall.com/lists/oss-security/2017/01/22/1nvdMailing ListPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2017/01/25/6nvdMailing ListPatchThird Party Advisory
- github.com/TigerVNC/tigervnc/commit/18c020124ff1b2441f714da2017f63dba50720banvdPatchThird Party Advisory
- github.com/TigerVNC/tigervnc/pull/399nvdPatchThird Party Advisory
- www.securityfocus.com/bid/95789nvdThird Party AdvisoryVDB Entry
- github.com/TigerVNC/tigervnc/releases/tag/v1.7.1nvdRelease NotesThird Party Advisory
- rhn.redhat.com/errata/RHSA-2017-0630.htmlnvd
- access.redhat.com/errata/RHSA-2017:2000nvd
- security.gentoo.org/glsa/201702-19nvd
News mentions
0No linked articles in our index yet.