CVE-2017-5884: Fedoraproject Fedora
High severity, CVSS 7.8. EPSS: 2.2% chance of exploitation in the next 30 days.
gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.
Affected products
- Fedoraproject Fedora: version 25 only
- Gnome Gtk-Vnc: up to and including 0.6.0
Published 2017-02-28. Last modified 2026-06-17.