PT-2018-1889 · Libvncserver+7 · Libvncserver+7
Alexander Peslyak
·
Published
2018-02-18
·
Updated
2021-01-15
·
CVE-2018-7225
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LibVNCServer versions prior to 0.9.12
Description
The issue is related to insufficient sanitization of VNC packet input data in the
rfbProcessClientNormalMessage() function of the LibVNCServer library. This can be exploited by a remote attacker to cause a denial of service and gain unauthorized access to sensitive data. The vulnerability is triggered by specially crafted VNC packets, which can lead to access to uninitialized and potentially sensitive data, or possibly other impacts such as an integer overflow.Recommendations
For LibVNCServer versions prior to 0.9.12, update to version 0.9.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the
rfbProcessClientNormalMessage() function to minimize the risk of exploitation.Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Centos
Libvncserver
Linuxmint
Red Hat
Suse
Ubuntu