CVE-2009-0388

Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code via a large length value in a message, related to the (a) ClientConnection::CheckBufferSize and (b) ClientConnection::CheckFileZipBufferSize functions in ClientConnection.cpp.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
tightvnctightvnc
1.3.9
ultravncultravnc
1.0.2
ultravncultravnc
1.0.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tightvnc
bullseye
1:1.3.10-3
fixed
bookworm
1:1.3.10-7
fixed
sid
1:1.3.10-9
fixed
trixie
1:1.3.10-9
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tightvnc
karmic
not-affected
jaunty
not-affected
intrepid
not-affected
hardy
not-affected
gutsy
ignored
dapper
ignored
Common Weakness Enumeration