Core Security Technologies Advisory – Multiple integer overflow vulnerabilities have been discovered in UltraVNC and TightVNC, two (open source) remote control applications derived from the popular VNC software. The vulnerabilities cause a miscalculation of a buffer size on the heap, allowing an attacker to corrupt a VNC client heap and can probably allow code execution (exploitation is very likely). Affected packages include UltraVNC versions 1.0.2, 1.0.5, and TightVNC version 1.3.9.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/74610/CORE-2008-1009.txt
Source: https://packetstormsecurity.com/files/74610/Core-Security-Technologies-Advisory-2008.1009.html

