LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Improper Initialization vulnerability in VNC client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it can be used to leak stack memory layout and in bypassing ASLR
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1617-1 | libvncserver security update |
Debian DLA |
DLA-1979-1 | italc security update |
Debian DLA |
DLA-2016-1 | ssvnc security update |
Debian DLA |
DLA-2045-1 | tightvnc security update |
Debian DSA |
DSA-4383-1 | libvncserver security update |
EUVD |
EUVD-2018-12600 | LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Improper Initialization vulnerability in VNC client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it can be used to leak stack memory layout and in bypassing ASLR |
Ubuntu USN |
USN-3877-1 | LibVNCServer vulnerabilities |
Ubuntu USN |
USN-4547-1 | iTALC vulnerabilities |
Ubuntu USN |
USN-4547-2 | SSVNC vulnerabilities |
Ubuntu USN |
USN-4587-1 | iTALC vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: Kaspersky
Published:
Updated: 2024-08-05T11:51:18.317Z
Reserved: 2018-12-10T00:00:00
Link: CVE-2018-20022
No data.
Status : Modified
Published: 2018-12-19T16:29:00.467
Modified: 2024-11-21T04:00:46.457
Link: CVE-2018-20022
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN