CVE-2018-7225
An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 6.11% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- libvncserver project/libvncserver · debian/debian linux · canonical/ubuntu linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2018/02/18/1Exploit, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/103107Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1055Third Party Advisory
- https://github.com/LibVNC/libvncserver/issues/218Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00035.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00042.html
- https://lists.debian.org/debian-lts-announce/2019/11/msg00032.html
- https://lists.debian.org/debian-lts-announce/2019/12/msg00028.html
- https://security.gentoo.org/glsa/201908-05
- https://usn.ubuntu.com/3618-1/Third Party Advisory
- https://usn.ubuntu.com/4547-1/
- https://usn.ubuntu.com/4573-1/
- https://usn.ubuntu.com/4587-1/
- https://www.debian.org/security/2018/dsa-4221Third Party Advisory
- http://www.openwall.com/lists/oss-security/2018/02/18/1Exploit, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/103107Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1055Third Party Advisory
- https://github.com/LibVNC/libvncserver/issues/218Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00035.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00042.html
- https://lists.debian.org/debian-lts-announce/2019/11/msg00032.html
- https://lists.debian.org/debian-lts-announce/2019/12/msg00028.html
- https://security.gentoo.org/glsa/201908-05
- https://usn.ubuntu.com/3618-1/Third Party Advisory
- https://usn.ubuntu.com/4547-1/
- https://usn.ubuntu.com/4573-1/
- https://usn.ubuntu.com/4587-1/
- https://www.debian.org/security/2018/dsa-4221Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.