---
title: "CVE-2008-4770\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2008-4770?format=md
keywords: index, follow
---

# CVE-2008-4770

Publication date 16 January 2009

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The CMsgReader::readRect function in the VNC Viewer component in RealVNC
VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2,
and Personal Edition P4.0 through P4.4.2 allows remote VNC servers to
execute arbitrary code via crafted RFB protocol data, related to "encoding
type."

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| vnc4 | 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.10 maverick | Not affected |
| 10.04 LTS lucid | Not affected |
| 9.10 karmic | Ignored end of life |
| 9.04 jaunty | Ignored end of life |
| 8.10 intrepid | Ignored end of life, was needed |
| 8.04 LTS hardy | Ignored end of life |
| 7.10 gutsy | Ignored end of life, was needed |
| 6.06 LTS dapper | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2008-4770?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| vnc4 | * Vendor:   <https://bugzilla.redhat.com/attachment.cgi?id=329323> * Vendor:   <http://patch-tracking.debian.net/patch/series/view/vnc4/4.1.1+X4.3.0-31/vnc-CVE-2008-4770.diff> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4770)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2008-4770)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2008-4770)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2008-4770)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2008-4770>
