cbcvebase.
CVE-2018-7225
published 2018-02-19

CVE-2018-7225: An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
david_kingvino>= 0 < 3.22.0-63.22.0-6
david_kingvino>= 0 < 3.22.0-63.22.0-6
david_kingvino>= 0 < 3.8.1-0ubuntu9.33.8.1-0ubuntu9.3
david_kingvino>= 0 < 3.22.0-3ubuntu1.13.22.0-3ubuntu1.1
david_kingvino>= 0 < 3.22.0-5ubuntu2.13.22.0-5ubuntu2.1
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianlibvncserver< libvncserver 0.9.11+dfsg-1.1 (bookworm)libvncserver 0.9.11+dfsg-1.1 (bookworm)
debiantightvnc< libvncserver 0.9.11+dfsg-1.1 (bookworm)libvncserver 0.9.11+dfsg-1.1 (bookworm)
debianvino< libvncserver 0.9.11+dfsg-1.1 (bookworm)libvncserver 0.9.11+dfsg-1.1 (bookworm)
libvncserver_projectlibvncserver<= 0.9.11
libvncserver_projectlibvncserver>= 0 < 0.9.11+dfsg-1.10.9.11+dfsg-1.1
libvncserver_projectlibvncserver>= 0 < 0.9.11+dfsg-1.10.9.11+dfsg-1.1
libvncserver_projectlibvncserver>= 0 < 0.9.11+dfsg-1.10.9.11+dfsg-1.1
libvncserver_projectlibvncserver>= 0 < 0.9.11+dfsg-1.10.9.11+dfsg-1.1
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL