CVE-2018-15126: Use After Free
Published Dec 19, 2018
·Updated
Last updated 24 July 2024
Other sources
LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution
Affected Software
8 affected componentsFixes available
Libvnc Project Libvncserver<0.9.12
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/libvncserver
0.9.13+dfsg-2+deb11u10.9.14+dfsg-10.9.15+dfsg-1
Remediation
Event History
Dec 19, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Data Sourced
04:29 PM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:52 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:58 AM
RemedyDescriptionSeverityAffected Software
Apr 20, 2025
Data Sourced
via Debian·04:01 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2018-15126?
CVE-2018-15126 is a heap use-after-free vulnerability in the server code of LibVNC's file transfer extension.
2
How severe is CVE-2018-15126?
CVE-2018-15126 has a severity rating of 9.8 out of 10, which is considered critical.
3
What software versions are affected by CVE-2018-15126?
CVE-2018-15126 affects LibVNC server versions up to and excluding 0.9.12.
4
How can I fix CVE-2018-15126?
To fix CVE-2018-15126, update to the patched versions provided by the software vendor.
5
Where can I find more information about CVE-2018-15126?
More information about CVE-2018-15126 can be found in the references section of this advisory.