PT-2018-2455 · Libvnc+3 · Libvnc+3
Pavel Cheremushkin
·
Published
2018-08-14
·
Updated
2019-10-31
·
CVE-2018-15126
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
LibVNC versions prior to commit 73cb96fec028a576a5a24417b57723b55854ad7b
Description
The issue is related to a heap use-after-free vulnerability in the server code of the file transfer extension. This vulnerability can result in remote code execution.
Recommendations
For versions prior to commit 73cb96fec028a576a5a24417b57723b55854ad7b, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the file transfer extension until a patch is available. Restrict access to the server code to minimize the risk of exploitation.
Fix
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Libvnc
Suse
Ubuntu