LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Improper Initialization vulnerability in VNC client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it can be used to leak stack memory layout and in bypassing ASLR
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade veyonUpgrade libvncserverUpgrade ssvncUpgrade tightvnc | Feb 4, 2019 | Dec 19, 2018 |
| Gentoo Linux | — | Upgrade net-libs/libvncserver.Upgrade net-misc/ssvnc. | Aug 13, 2019 | Dec 19, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libvncserver | Feb 22, 2019 | Dec 19, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libvncserver | Mar 27, 2019 | Dec 19, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libvncserver | Feb 15, 2019 | Dec 19, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 19, 2018 |
| Suse | — | Upgrade LibVNCServer-develUpgrade libvncserver0Upgrade LibVNCServerUpgrade libvncclient0 | Jan 11, 2019 | Dec 19, 2018 |
| Ubuntu | — | Upgrade libvncserver1Upgrade libitalccoreUpgrade italc-masterUpgrade libvncserver0Upgrade ssvncUpgrade libvncclient1Upgrade italc-client | Feb 6, 2019 | Dec 19, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub