UltraVNC revision 1205 has stack-based buffer overflow vulnerability in VNC client code inside ShowConnInfo routine, which leads to a denial of service (DoS) condition. This attack appear to be exploitable via network connectivity. User interaction is required to trigger this vulnerability. This vulnerability has been fixed in revision 1206.
| Software | From | Fixed in |
|---|---|---|
| uvnc / ultravnc | - | 1.2.2.3 |
| siemens / sinumerik_pcu_base_win7_software/ipc | - | 12.01.x |
| siemens / sinumerik_pcu_base_win10_software/ipc | - | 14.00 |
| siemens / sinumerik_access_mymachine/p2p | - | 4.8 |