CVE-2018-15127: Critical severity libvncserver vulnerability
Last updated 24 July 2024
Other sources
LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains a heap out-of-bound write vulnerability in the server code of the file transfer extension, which can result in remote code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in 502821828ed00b4a2c4bef90683d0fd88ce495de and later.
External Reference:
https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/12/19/klcert-18-028-libvnc-heap-out-of-bound-write/
Upstream Patch:
https://github.com/LibVNC/libvncserver/commit/502821828ed00b4a2c4bef90683d0fd88ce495de
— Red Hat
LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15127?
The severity of CVE-2018-15127 is critical with a severity value of 9.8.
What is the description of CVE-2018-15127?
CVE-2018-15127 is a heap out-of-bound write vulnerability in the server code of the file transfer extension in LibVNC, which can result in remote code execution.
Which software versions are affected by CVE-2018-15127?
The affected software versions are LibVNC 0.9.11+dfsg-1ubuntu1.1, 0.9.11+dfsg-1.1ubuntu0.1, 0.9.9+dfsg-1ubuntu1.4, 0.9.11+dfsg-1.2, 0.9.10+dfsg-3ubuntu0.16.04.3, and more.
How can I fix CVE-2018-15127?
To fix CVE-2018-15127, update the LibVNC package to version 0.9.11+dfsg-1ubuntu1.1 or apply the appropriate remedy provided by your OS vendor.
Where can I find more information about CVE-2018-15127?
You can find more information about CVE-2018-15127 on the following references: [link1], [link2], [link3].