CVE-2017-18922: Buffer Overflow
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.
Other sources
libvncserver container a heap-based buffer overflow within the websocket decoding functionality, which can be exploited by a malicious attacker to overwrite a function pointer.
Patch: https://github.com/LibVNC/libvncserver/commit/aac95a9dcf4bbba87b76c72706c3221a842ca433
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.12 - Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6 - Upgrade
Upgrade
LibVNCServer (libvncserver)to a version that resolves this vulnerability.Fixed in 0.9.12Patch aac95a9dcf4bbba87b76c72706c3221a842ca433
Event History
Frequently Asked Questions
What is CVE-2017-18922?
CVE-2017-18922 is a vulnerability in LibVNCServer that allows a malicious attacker to cause a heap-based buffer overflow by sending specially crafted WebSocket frames.
How severe is CVE-2017-18922?
CVE-2017-18922 has a severity rating of 9.8 out of 10, making it a critical vulnerability.
Which software versions are affected by CVE-2017-18922?
The affected software versions for CVE-2017-18922 include LibVNCServer prior to 0.9.12.
How can I fix CVE-2017-18922?
To fix CVE-2017-18922, you should update LibVNCServer to version 0.9.12 or later.
Where can I find more information about CVE-2017-18922?
More information about CVE-2017-18922 can be found on the CVE website at https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18922.