7.5
CVSSv2

CVE-2018-20749

Published: 30/01/2019 Updated: 09/03/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

LibVNC prior to 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libvnc project libvncserver

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

debian debian linux 8.0

debian debian linux 9.0

siemens simatic_itc1500_firmware

siemens simatic_itc1500_pro_firmware

siemens simatic_itc1900_firmware

siemens simatic_itc1900_pro_firmware

siemens simatic_itc2200_firmware

siemens simatic_itc2200_pro_firmware

Vendor Advisories

Debian Bug report logs - #920941 libvncserver: CVE-2018-20748 CVE-2018-20749 CVE-2018-20750 Package: src:libvncserver; Maintainer for src:libvncserver is Peter Spiess-Knafl <dev@spiessknaflat>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 30 Jan 2019 18:21:01 UTC Severity: grave Tags: patch, secu ...
Several security issues were fixed in LibVNCServer ...