LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code execution
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade veyonUpgrade libvncserverUpgrade ssvnc | Feb 4, 2019 | Dec 19, 2018 |
| Gentoo Linux | — | Upgrade net-libs/libvncserver.Upgrade net-misc/ssvnc. | Aug 13, 2019 | Dec 19, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libvncserver | Feb 22, 2019 | Dec 19, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libvncserver | Mar 27, 2019 | Dec 19, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libvncserver | Feb 15, 2019 | Dec 19, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 19, 2018 |
| Suse | — | Upgrade LibVNCServer-develUpgrade libvncclient0Upgrade libvncserver0Upgrade LibVNCServer | Jan 11, 2019 | Dec 19, 2018 |
| Ubuntu | — | Upgrade libvncserver1Upgrade italc-masterUpgrade libvncclient1Upgrade libitalccoreUpgrade italc-clientUpgrade libvncserver0Upgrade ssvnc | Feb 6, 2019 | Dec 19, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub