gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.
[ { "events": [ { "introduced": "0" }, { "last_affected": "25" } ] }, { "events": [ { "introduced": "0" }, { "last_affected": "0.6.0" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5884.json"