CVE-2018-20022: High severity Libvnc Project Libvncserver vulnerability
Last updated 11 July 2025
Other sources
LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Improper Initialization vulnerability in VNC client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it can be used to leak stack memory layout and in bypassing ASLR
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6 - Upgrade
Upgrade
debian/ssvncto a version that resolves this vulnerability.Fixed in 1.0.29-5Fixed in 1.0.29-6Fixed in 1.0.29-6.1Fixed in 1.0.29-7 - Upgrade
Upgrade
debian/tightvncto a version that resolves this vulnerability.Fixed in 1:1.3.10-3Fixed in 1:1.3.10-7Fixed in 1:1.3.10-9Fixed in 1:1.3.10-11 - Upgrade
Upgrade
debian/veyonto a version that resolves this vulnerability.Fixed in 4.5.3+repack1-1Fixed in 4.7.5+repack1-1Fixed in 4.9.5+repack1-2Fixed in 4.9.7+repack1-1.1 - Upgrade
Upgrade
LibVNCto a version that resolves this vulnerability.Patch 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838
Event History
Frequently Asked Questions
What is CVE-2018-20022?
CVE-2018-20022 is a vulnerability in LibVNC that allows an attacker to read stack memory and potentially leak sensitive information.
How severe is CVE-2018-20022?
CVE-2018-20022 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2018-20022?
CVE-2018-20022 affects LibVNC before version 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838.
How can I fix the CVE-2018-20022 vulnerability?
To fix the CVE-2018-20022 vulnerability, update to LibVNC version 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 or apply the necessary patches.
Where can I find more information about CVE-2018-20022?
You can find more information about CVE-2018-20022 at the following references: [GitHub Issue](https://github.com/LibVNC/libvncserver/issues/252), [GitHub Commit](https://github.com/LibVNC/libvncserver/commit/2f5b2ad1c6c99b1ac6482c95844a84d66bb52838), [Kaspersky Advisory](https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/12/19/klcert-18-032-libvnc-multiple-memory-leaks/).