LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665: Improper Initialization vulnerability in VNC Repeater client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it can be used to leak stack memory layout and in bypassing ASLR
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1617-1 | libvncserver security update |
Debian DLA |
DLA-1979-1 | italc security update |
Debian DSA |
DSA-4383-1 | libvncserver security update |
EUVD |
EUVD-2018-12601 | LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665: Improper Initialization vulnerability in VNC Repeater client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it can be used to leak stack memory layout and in bypassing ASLR |
Ubuntu USN |
USN-3877-1 | LibVNCServer vulnerabilities |
Ubuntu USN |
USN-4547-1 | iTALC vulnerabilities |
Ubuntu USN |
USN-4587-1 | iTALC vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: Kaspersky
Published:
Updated: 2024-08-05T11:51:18.305Z
Reserved: 2018-12-10T00:00:00
Link: CVE-2018-20023
No data.
Status : Modified
Published: 2018-12-19T16:29:00.513
Modified: 2024-11-21T04:00:46.597
Link: CVE-2018-20023
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN