CVE-2018-21247

Severity
7.5HIGH
EPSS
1.5%
top 19.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 17
Latest updateMay 24

Description

An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages9 packages

Debianlibvncserver< 0.9.11+dfsg-1.2+3
NVDsiemens/simatic_itc1500_firmware3.0.0.03.2.1.0
NVDsiemens/simatic_itc1900_firmware3.0.0.03.2.1.0
NVDsiemens/simatic_itc2200_firmware3.0.0.03.2.1.0

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 18.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-355f-mpqr-3mwv: An issue was discovered in LibVNCServer before 02022-05-24
CVEList
CVE-2018-21247: An issue was discovered in LibVNCServer before 02020-06-17
OSV
CVE-2018-21247: An issue was discovered in LibVNCServer before 02020-06-17

📋Vendor Advisories

2
Red Hat
libvncserver: uninitialized memory contents are vulnerable to Information Leak2020-06-17
Debian
CVE-2018-21247: libvncserver - An issue was discovered in LibVNCServer before 0.9.13. There is an information l...2018

💬Community

3
Bugzilla
CVE-2018-21247 libvncserver: uninitialized memory contents are vulnerable to Information Leak [fedora-all]2020-06-23
Bugzilla
CVE-2018-21247 libvncserver: uninitialized memory contents are vulnerable to Information Leak2020-06-23
Bugzilla
CVE-2018-21247 libvncserver: uninitialized memory contents are vulnerable to Information Leak [epel-7]2020-06-23