LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade veyonUpgrade libvncserver | Feb 20, 2019 | Jan 30, 2019 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libvncserver | Feb 22, 2019 | Jan 30, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libvncserver | Mar 27, 2019 | Jan 30, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libvncserver | Mar 11, 2019 | Jan 30, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 30, 2019 |
| Suse | — | Upgrade LibVNCServer-develUpgrade libvncserver0Upgrade LibVNCServerUpgrade libvncclient0 | Feb 12, 2019 | Jan 30, 2019 |
| Ubuntu | — | Upgrade libitalccoreUpgrade libvncserver0Upgrade italc-masterUpgrade libvncserver1Upgrade libvncclient1Upgrade italc-client | Feb 6, 2019 | Jan 30, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub