{"id":"CVE-2017-5581","details":"Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE message with subrectangle outside framebuffer boundaries.","modified":"2026-05-18T11:38:28.533814Z","published":"2017-02-28T18:59:00.360Z","references":[{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2017-0630.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/95789"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:2000"},{"type":"ADVISORY","url":"https://github.com/TigerVNC/tigervnc/releases/tag/v1.7.1"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201702-19"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2017/01/22/1"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2017/01/25/6"},{"type":"FIX","url":"https://github.com/TigerVNC/tigervnc/commit/18c020124ff1b2441f714da2017f63dba50720ba"},{"type":"FIX","url":"https://github.com/TigerVNC/tigervnc/pull/399"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tigervnc/tigervnc","events":[{"introduced":"0"},{"last_affected":"e25272fc74ef09987ccaa33b9bf1736397c76fdf"}],"database_specific":{"cpe":"cpe:2.3:a:tigervnc:tigervnc:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.7"}],"source":"CPE_FIELD"}}],"versions":["v1.7.0","v1.6.90","v1.1.90","v0.0.90"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-5581.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}