Severity
9.8CRITICAL
EPSS
4.8%
top 10.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 30
Latest updateMay 24

Description

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages9 packages

Debianlibvncserver< 0.9.12+dfsg-3+3
NVDsiemens/simatic_itc1500_firmware3.0.0.03.2.1.0
NVDsiemens/simatic_itc1900_firmware3.0.0.03.2.1.0
NVDsiemens/simatic_itc2200_firmware3.0.0.03.2.1.0

Also affects: Fedora 31, 32, Ubuntu Linux 16.04, 18.04, 19.10, 20.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-hq8f-cpqj-qph2: It was discovered that websockets2022-05-24
OSV
CVE-2017-18922: It was discovered that websockets2020-06-30
CVEList
CVE-2017-18922: It was discovered that websockets2020-06-30

📋Vendor Advisories

3
Ubuntu
LibVNCServer vulnerabilities2020-07-01
Red Hat
libvncserver: websocket decoding buffer overflow2017-02-15
Debian
CVE-2017-18922: libvncserver - It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not prop...2017

💬Community

2
Bugzilla
CVE-2017-18922 libvncserver: websocket decoding buffer overflow2020-06-30
Bugzilla
CVE-2017-18922 libvncserver: websocket decoding buffer overflow [fedora-all]2020-06-30