CVE-2019-15693

Source
https://cve.org/CVERecord?id=CVE-2019-15693
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-15693.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-15693
Downstream
Related
Published
2019-12-26T15:15:11.257Z
Modified
2026-01-30T17:06:10.808521Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which occurs in TightDecoder::FilterGradient. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity.

References

Affected packages

Git / github.com/cendioossman/tigervnc

Affected ranges

Type
GIT
Repo
https://github.com/cendioossman/tigervnc
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.0.90
v1.*
v1.1.90

Database specific

vanir_signatures
[
    {
        "signature_type": "Function",
        "source": "https://github.com/cendioossman/tigervnc/commit/b4ada8d0c6dac98c8b91fc64d112569a8ae5fb95",
        "target": {
            "file": "common/rfb/tightDecode.h",
            "function": "TightDecoder::FilterGradient24"
        },
        "id": "CVE-2019-15693-0778f897",
        "signature_version": "v1",
        "digest": {
            "function_hash": "161533384762656642991908016226820675801",
            "length": 1114.0
        },
        "deprecated": false
    },
    {
        "signature_type": "Function",
        "source": "https://github.com/cendioossman/tigervnc/commit/b4ada8d0c6dac98c8b91fc64d112569a8ae5fb95",
        "target": {
            "file": "common/rfb/tightDecode.h",
            "function": "TightDecoder::FilterGradient"
        },
        "id": "CVE-2019-15693-0f28dc62",
        "signature_version": "v1",
        "digest": {
            "function_hash": "15078154590552314086322110788077167964",
            "length": 1241.0
        },
        "deprecated": false
    },
    {
        "signature_type": "Line",
        "source": "https://github.com/cendioossman/tigervnc/commit/b4ada8d0c6dac98c8b91fc64d112569a8ae5fb95",
        "target": {
            "file": "common/rfb/tightDecode.h"
        },
        "id": "CVE-2019-15693-88485049",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "293455449759008813589093370358687204021",
                "325843735815826093212861249029613301064",
                "136591138797822271697212927084004582351",
                "62052450669799827691813475708858346363",
                "337928664818970489339721796832910053544",
                "93143391051428726767418149145675560953",
                "317784546308526455607118808614036723427",
                "128344201559584871911909258738499665899",
                "177806965800441837721188648140893735849",
                "112483111471243258414108181407805726649",
                "339082532496385597166058674788704540274",
                "45688700836358365768598936923207689267",
                "142890125048347970355594432742912803847",
                "54921379597364198587993663848271405886",
                "8349089216622482553689210365120426753",
                "119047859076443823313001192459542761695",
                "128344201559584871911909258738499665899",
                "329093963382497243144142375750350552265"
            ]
        },
        "deprecated": false
    }
]
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-15693.json"

Git / github.com/tigervnc/tigervnc

Affected ranges

Type
GIT
Repo
https://github.com/tigervnc/tigervnc
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.0.90
v1.*
v1.1.90
v1.10.0
v1.9.90

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-15693.json"