CVE-2018-7225
Summary
| CVE | CVE-2018-7225 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-19 15:29:00 UTC |
| Updated | 2020-10-23 13:15:00 UTC |
| Description | An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2045-1] tightvnc security update |
MLIST |
lists.debian.org |
|
| Malformed Request |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| USN-4547-1: iTALC vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| USN-4573-1: Vino vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| [SECURITY] [DLA 1332-1] libvncserver security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 1979-1] italc security update |
MLIST |
lists.debian.org |
|
| oss-security - LibVNCServer rfbserver.c: rfbProcessClientNormalMessage() case rfbClientCutText doesn't sanitize msg.cct.length |
MISC |
www.openwall.com |
Exploit, Mailing List, Third Party Advisory |
| USN-4587-1: iTALC vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| USN-3618-1: LibVNCServer vulnerability | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Security: libvncserver/rfbserver.c: rfbProcessClientNormalMessage() case rfbClientCutText doesn't sanitize msg.cct.length · Issue #218 · LibVNC/libvncserver · GitHub |
MISC |
github.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| LibVNCServer: Multiple vulnerabilities (GLSA 201908-05) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] [DLA 2014-1] vino security update |
MLIST |
lists.debian.org |
|
| Debian -- Security Information -- DSA-4221-1 libvncserver |
DEBIAN |
www.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 501066 Alpine Linux Security Update for libvncserver
- 505049 Alpine Linux Security Update for libvncserver
- 710154 Gentoo Linux LibVNCServer Multiple vulnerabilities (GLSA 201908-05)