CVE-2018-20019: Critical severity Libvnc Project Libvncserver vulnerability
Last updated 25 August 2025
Other sources
LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC client code that can result remote code execution
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6 - Upgrade
Upgrade
LibVNCto a version that resolves this vulnerability.Patch a83439b9fbe0f03c48eb94ed05729cb016f8b72f
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20019?
The severity of CVE-2018-20019 is critical with a severity value of 9.8.
What is the description of CVE-2018-20019?
CVE-2018-20019 is a vulnerability in LibVNC that contains multiple heap out-of-bound write vulnerabilities in VNC client code, which can result in remote code execution.
How can I fix CVE-2018-20019 in Ubuntu?
To fix CVE-2018-20019 in Ubuntu, update the affected packages to the specified versions: italc (1:3.0.3+dfsg1-3ubuntu0.1) or italc (1:2.0.2+dfsg1-4ubuntu0.1) or libvncserver (0.9.11+dfsg-1ubuntu1.1) or libvncserver (0.9.11+dfsg-1.1ubuntu0.1) or libvncserver (0.9.9+dfsg-1ubuntu1.4) or libvncserver (0.9.11+dfsg-1.2) or libvncserver (0.9.10+dfsg-3ubuntu0.16.04.3).
How can I fix CVE-2018-20019 in Debian?
To fix CVE-2018-20019 in Debian, update the affected package libvncserver to one of the specified versions: 0.9.11+dfsg-1.3+deb10u4 or 0.9.11+dfsg-1.3+deb10u5 or 0.9.13+dfsg-2+deb11u1 or 0.9.14+dfsg-1.
Where can I find more information about CVE-2018-20019?
More information about CVE-2018-20019 can be found at the following references: [GitHub Issue](https://github.com/LibVNC/libvncserver/issues/247), [GitHub Commit](https://github.com/LibVNC/libvncserver/commit/a83439b9fbe0f03c48eb94ed05729cb016f8b72f), [ICS-CERT Advisory](https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/12/19/klcert-18-029-libvnc-multiple-heap-out-of-bound-vulnerabilities/).