First published: Wed Dec 19 2018(Updated: )
Last updated 24 July 2024
Credit: vulnerability@kaspersky.com vulnerability@kaspersky.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libvnc Project Libvncserver | <0.9.12 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =18.10 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Siemens Simatic Itc1500 Firmware | >=3.0.0.0<3.2.1.0 | |
Siemens Simatic Itc1500 | ||
Siemens Simatic Itc1500 Pro Firmware | >=3.0.0.0<3.2.1.0 | |
Siemens Simatic Itc1500 Pro | ||
Siemens Simatic Itc1900 Firmware | >=3.0.0.0<3.2.1.0 | |
Siemens Simatic Itc1900 | ||
Siemens Simatic Itc1900 Pro Firmware | >=3.0.0.0<3.2.1.0 | |
Siemens Simatic Itc1900 Pro | ||
Siemens Simatic Itc2200 Firmware | >=3.0.0.0<3.2.1.0 | |
Siemens Simatic Itc2200 | ||
Siemens Simatic Itc2200 Pro Firmware | >=3.0.0.0<3.2.1.0 | |
Siemens Simatic Itc2200 Pro | ||
All of | ||
Siemens Simatic Itc1500 Firmware | >=3.0.0.0<3.2.1.0 | |
Siemens Simatic Itc1500 | ||
All of | ||
Siemens Simatic Itc1500 Pro Firmware | >=3.0.0.0<3.2.1.0 | |
Siemens Simatic Itc1500 Pro | ||
All of | ||
Siemens Simatic Itc1900 Firmware | >=3.0.0.0<3.2.1.0 | |
Siemens Simatic Itc1900 | ||
All of | ||
Siemens Simatic Itc1900 Pro Firmware | >=3.0.0.0<3.2.1.0 | |
Siemens Simatic Itc1900 Pro | ||
All of | ||
Siemens Simatic Itc2200 Firmware | >=3.0.0.0<3.2.1.0 | |
Siemens Simatic Itc2200 | ||
All of | ||
Siemens Simatic Itc2200 Pro Firmware | >=3.0.0.0<3.2.1.0 | |
Siemens Simatic Itc2200 Pro | ||
debian/libvncserver | 0.9.13+dfsg-2+deb11u1 0.9.14+dfsg-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-20019 is critical with a severity value of 9.8.
CVE-2018-20019 is a vulnerability in LibVNC that contains multiple heap out-of-bound write vulnerabilities in VNC client code, which can result in remote code execution.
To fix CVE-2018-20019 in Ubuntu, update the affected packages to the specified versions: italc (1:3.0.3+dfsg1-3ubuntu0.1) or italc (1:2.0.2+dfsg1-4ubuntu0.1) or libvncserver (0.9.11+dfsg-1ubuntu1.1) or libvncserver (0.9.11+dfsg-1.1ubuntu0.1) or libvncserver (0.9.9+dfsg-1ubuntu1.4) or libvncserver (0.9.11+dfsg-1.2) or libvncserver (0.9.10+dfsg-3ubuntu0.16.04.3).
To fix CVE-2018-20019 in Debian, update the affected package libvncserver to one of the specified versions: 0.9.11+dfsg-1.3+deb10u4 or 0.9.11+dfsg-1.3+deb10u5 or 0.9.13+dfsg-2+deb11u1 or 0.9.14+dfsg-1.
More information about CVE-2018-20019 can be found at the following references: [GitHub Issue](https://github.com/LibVNC/libvncserver/issues/247), [GitHub Commit](https://github.com/LibVNC/libvncserver/commit/a83439b9fbe0f03c48eb94ed05729cb016f8b72f), [ICS-CERT Advisory](https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/12/19/klcert-18-029-libvnc-multiple-heap-out-of-bound-vulnerabilities/).