Multiple integer overflows in the (1) vncconnectionservermessage and (2) vnccolormapset functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.