Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-15127

Опубликовано: 19 дек. 2018
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvncserverWill not fix
Red Hat Enterprise Linux 8libvncserverNot affected
Red Hat Enterprise Linux 7libvncserverFixedRHSA-2019:005915.01.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1661102libvncserver: Heap out-of-bounds write in rfbserver.c in rfbProcessFileTransferReadBuffer() allows for potential code execution

EPSS

Процентиль: 94%
0.15621
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 7 лет назад

LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution

CVSS3: 9.8
nvd
почти 7 лет назад

LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution

CVSS3: 9.8
debian
почти 7 лет назад

LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains ...

CVSS3: 9.8
github
больше 3 лет назад

LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution

oracle-oval
почти 7 лет назад

ELSA-2019-0059: libvncserver security update (IMPORTANT)

EPSS

Процентиль: 94%
0.15621
Средний

7.5 High

CVSS3