diff options
| author | Josef Gajdusek <atx@atx.name> | 2016-11-14 11:39:01 +0100 |
|---|---|---|
| committer | Josef Gajdusek <atx@atx.name> | 2016-11-14 12:51:44 +0100 |
| commit | 5418e8007c248bf9668d22a8c1fa9528149b69f2 (patch) | |
| tree | 5c9f562d38caced45a2d7eebf62e7cd0270e1958 /webclients/java-applet/ssl | |
| parent | 3df54ce7ce2e126a7e5f88c4ae1f515509abc19b (diff) | |
| download | libtdevnc-5418e8007c248bf9668d22a8c1fa9528149b69f2.tar.gz libtdevnc-5418e8007c248bf9668d22a8c1fa9528149b69f2.zip | |
Fix heap overflows in the various rectangle fill functions
Altough rfbproto.c does check whether the overall FramebufferUpdate rectangle is
too large, some of the individual encoding decoders do not, which allows a
malicious server to overwrite parts of the heap.
Diffstat (limited to 'webclients/java-applet/ssl')
0 files changed, 0 insertions, 0 deletions
