Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-15126

Опубликовано: 19 дек. 2018
Источник: redhat
CVSS3: 7.5

Описание

LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution

Отчет

This issue did not affect the versions of libvncserver as shipped with Red Hat Enterprise Linux 6 and 7, as they did not include support for tightvnc file transfer.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvncserverNot affected
Red Hat Enterprise Linux 7libvncserverNot affected
Red Hat Enterprise Linux 8libvncserverNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1661110libvncserver: Use-after-free in file transfer extension allows for potential code execution

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 7 лет назад

LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution

CVSS3: 9.8
nvd
около 7 лет назад

LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution

CVSS3: 9.8
debian
около 7 лет назад

LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains ...

CVSS3: 9.8
github
больше 3 лет назад

LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution

CVSS3: 9.8
fstec
больше 7 лет назад

Уязвимость библиотеки LibVNC, связанная с использованием памяти после её освобождения, позволяющая нарушителю выполнить произвольный код

7.5 High

CVSS3