PT-2019-1356 · Libvnc+3 · Libvnc+4

Pavel Cheremushkin

·

Published

2019-01-07

·

Updated

2022-03-10

·

CVE-2018-20750

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LibVNC through 0.9.12
Description The issue is related to a heap out-of-bounds write vulnerability in the rfbserver.c component of the LibVNCServer library. This vulnerability can be exploited by a remote attacker to cause a denial of service and gain unauthorized access to sensitive data.
Recommendations For LibVNC through 0.9.12, consider applying the necessary patches or fixes to address the incomplete fix for the issue. As a temporary workaround, restrict access to the vulnerable rfbserver.c component to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2585
ALT-PU-2019-2662
ALT-PU-2021-1040
BDU:2019-00704
CVE-2018-20750
DLA-1652-1
DLA-1979-1
MGASA-2019-0070
MGASA-2020-0435
OPENSUSE-SU-2019:0196-1
OPENSUSE-SU-2019_0196-1
OPENSUSE-SU-2019_0200-1
OPENSUSE-SU-2024:10598-1
SUSE-SU-2019:0283-1
SUSE-SU-2019:0313-1
SUSE-SU-2019:0313-2
SUSE-SU-2019:13952-1
USN-3877-1
USN-4547-1
USN-4587-1

Affected Products

Alt Linux
Libvnc
Libvncserver
Suse
Ubuntu