Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-1652
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-1652

Description:
Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-assisted remote attackers to execute arbitrary code via a malicious server that sends a long string to a client that connects on TCP port 5900, which triggers an overflow in Log::ReallyPrint; and (2) allow remote attackers to cause a denial of service (server crash) via a long HTTP GET request to TCP port 5800, which triggers an overflow in VNCLog::ReallyPrint.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/25650
  http://xforce.iss.net/xforce/xfdb/25648

SREASON
  http://securityreason.com/securityalert/674

SAID
  Secunia Advisory: SA19513

MILW0RM
  http://milw0rm.com/exploits/1643
  http://milw0rm.com/exploits/1642

FULLDISC
  http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044901.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/430711/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/430287/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/429930/100/0/threaded

BID
  17378


Return to the previous page.