PT-2018-3545 · Libvncserver+6 · Libvncserver+6
Pavel Cheremushkin
·
Publicado
2018-09-11
·
Atualizado
2022-03-10
·
CVE-2018-21247
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
LibVNCServer versions prior to 0.9.13
Description:
The issue is related to the implementation of the ConnectToRFBRepeater function in the LibVNCServer library, which lacks protection of service data. This can lead to an information leak of uninitialized memory contents. Exploitation of this issue may allow a remote attacker to cause a denial of service.
Recommendations:
For versions prior to 0.9.13, update to version 0.9.13 or later to resolve the issue.
As a temporary workaround, consider disabling the ConnectToRFBRepeater function until a patch is available.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Almalinux
Centos
Libvncserver
Red Hat
Rocky Linux
Suse