vulnerability

Red Hat: CVE-2018-21247: CVE-2018-21247 libvncserver: uninitialized memory contents are vulnerable to Information Leak (Multiple Advisories)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Jun 17, 2020
Added
May 21, 2021
Modified
Aug 11, 2025

Description

An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.

Solutions

no-fix-redhat-rpm-packageredhat-upgrade-libvncserverredhat-upgrade-libvncserver-debuginforedhat-upgrade-libvncserver-debugsourceredhat-upgrade-libvncserver-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.