PT-2018-2455 · Libvnc+3 · Libvnc+3

Pavel Cheremushkin

·

Published

2018-08-14

·

Updated

2019-10-31

·

CVE-2018-15126

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LibVNC versions prior to commit 73cb96fec028a576a5a24417b57723b55854ad7b
Description The issue is related to a heap use-after-free vulnerability in the server code of the file transfer extension. This vulnerability can result in remote code execution.
Recommendations For versions prior to commit 73cb96fec028a576a5a24417b57723b55854ad7b, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the file transfer extension until a patch is available. Restrict access to the server code to minimize the risk of exploitation.

Fix

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2585
ALT-PU-2019-2662
BDU:2019-00694
CVE-2018-15126
DLA-1652-1
DLA-1979-1
DSA-4383-1
MGASA-2019-0037
OPENSUSE-SU-2019:0053-1
OPENSUSE-SU-2019_0045-1
OPENSUSE-SU-2019_0053-1
OPENSUSE-SU-2024:10598-1
SUSE-SU-2019:0060-1
SUSE-SU-2019:0060-2
SUSE-SU-2019:0080-1
SUSE-SU-2019:13927-1
SUSE-SU-2019_0060-1
SUSE-SU-2019_0060-2
SUSE-SU-2019_0080-1
SUSE-SU-2019_13927-1
USN-3877-1

Affected Products

Alt Linux
Libvnc
Suse
Ubuntu