RULE(RULE ID:713763)

Rule General Information
Release Date: 2019-11-26
Rule Name: TightVNC vncviewer rfbServerCutText Handler Integer Overflow Vulnerability -2 (CVE-2019-15678)
Severity:
CVE ID:
Rule Protection Details
Description: TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via network connectivity.
Impact: An attacker can exploit the affected software with a integer overflow vulnerability. Successful exploit leads to execute arbitrary code, and failed exploit may disturb the software logic and cause denial of service.
Affected OS: Windows, Others
Reference: https://www.openwall.com/lists/oss-security/2018/12/10/5
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.tightvnc.com