Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-20020

Опубликовано: 19 дек. 2018
Источник: debian

Описание

LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code execution

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libvncserverfixed0.9.11+dfsg-1.2package
italcremovedpackage
italcnot-affectedstretchpackage
ssvncfixed1.0.29-5package
ssvncfixed1.0.29-4+deb10u1busterpackage
ssvncfixed1.0.29-3+deb9u1stretchpackage
veyonfixed4.1.4+repack1-1package

Примечания

  • https://github.com/LibVNC/libvncserver/issues/250

  • https://github.com/LibVNC/libvncserver/commit/09f2f3fb6a5a163e453e5c2979054670c39694bc

  • https://github.com/LibVNC/libvncserver/commit/7b1ef0ffc4815cab9a96c7278394152bdc89dc4d

  • https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/12/19/klcert-18-030-libvnc-heap-out-of-bound-write/

  • same as CVE-2019-8287/tightvnc

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 7 лет назад

LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code execution

CVSS3: 8.8
redhat
около 7 лет назад

LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code execution

CVSS3: 9.8
nvd
около 7 лет назад

LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code execution

CVSS3: 9.8
github
больше 3 лет назад

LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code execution

CVSS3: 9.8
fstec
больше 7 лет назад

Уязвимость библиотеки LibVNC, связанная со считыванием данных за пределами заданного буфера, позволяющая нарушителю выполнить произвольный код