PT-2019-1356 · Libvnc+3 · Libvnc+4
Pavel Cheremushkin
·
Published
2019-01-07
·
Updated
2022-03-10
·
CVE-2018-20750
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
LibVNC through 0.9.12
Description
The issue is related to a heap out-of-bounds write vulnerability in the rfbserver.c component of the LibVNCServer library. This vulnerability can be exploited by a remote attacker to cause a denial of service and gain unauthorized access to sensitive data.
Recommendations
For LibVNC through 0.9.12, consider applying the necessary patches or fixes to address the incomplete fix for the issue. As a temporary workaround, restrict access to the vulnerable
rfbserver.c component to minimize the risk of exploitation.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Libvnc
Libvncserver
Suse
Ubuntu