Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-18922

Опубликовано: 15 фев. 2017
Источник: redhat
CVSS3: 9.8

Описание

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

A flaw was found in libvncserver. A heap-based buffer overflow within the websocket decoding functionality is possible, which can lead to exploitation by a malicious attacker to overwrite a function pointer. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvncserverNot affected
Red Hat Enterprise Linux 7libvncserverFixedRHSA-2020:328103.08.2020
Red Hat Enterprise Linux 8libvncserverFixedRHSA-2020:338510.08.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionslibvncserverFixedRHSA-2020:358801.09.2020
Red Hat Enterprise Linux 8.1 Extended Update SupportlibvncserverFixedRHSA-2020:345617.08.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1852356libvncserver: websocket decoding buffer overflow

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

CVSS3: 9.8
nvd
больше 5 лет назад

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

CVSS3: 9.8
debian
больше 5 лет назад

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 di ...

suse-cvrf
больше 5 лет назад

Security update for LibVNCServer

suse-cvrf
больше 5 лет назад

Security update for LibVNCServer

9.8 Critical

CVSS3