Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-18922

Опубликовано: 30 июн. 2020
Источник: debian
EPSS Низкий

Описание

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libvncserverfixed0.9.12+dfsg-3package
libvncserverignoredbusterpackage
libvncserverignoredstretchpackage

Примечания

  • https://github.com/LibVNC/libvncserver/commit/aac95a9dcf4bbba87b76c72706c3221a842ca433

  • https://www.openwall.com/lists/oss-security/2020/06/30/2

EPSS

Процентиль: 89%
0.04777
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

CVSS3: 9.8
redhat
почти 9 лет назад

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

CVSS3: 9.8
nvd
больше 5 лет назад

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

suse-cvrf
больше 5 лет назад

Security update for LibVNCServer

suse-cvrf
больше 5 лет назад

Security update for LibVNCServer

EPSS

Процентиль: 89%
0.04777
Низкий