CVE-2018-20024: Null Pointer Dereference
Last updated 18 August 2025
Other sources
LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6 - Upgrade
Upgrade
debian/ssvncto a version that resolves this vulnerability.Fixed in 1.0.29-5Fixed in 1.0.29-6Fixed in 1.0.29-6.1Fixed in 1.0.29-7 - Upgrade
Upgrade
debian/veyonto a version that resolves this vulnerability.Fixed in 4.5.3+repack1-1Fixed in 4.7.5+repack1-1Fixed in 4.9.5+repack1-2Fixed in 4.9.7+repack1-1.1 - Upgrade
Upgrade
LibVNCto a version that resolves this vulnerability.Patch 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7
Event History
Frequently Asked Questions
What is CVE-2018-20024?
CVE-2018-20024 is a vulnerability in LibVNC that involves a null pointer dereference in VNC client code, which can result in a denial-of-service (DoS) attack.
How severe is CVE-2018-20024?
CVE-2018-20024 has a severity rating of 7.5, which is considered high.
What software is affected by CVE-2018-20024?
The affected software includes LibVNC versions up to exclusive 0.9.11+dfsg-1.1ubuntu0.1, 0.9.11+dfsg-1ubuntu1.1, 0.9.9+dfsg-1ubuntu1.4, and 0.9.11+dfsg-1.2.
How can I fix CVE-2018-20024?
To fix CVE-2018-20024, update your LibVNC installation to version 0.9.11+dfsg-1.1ubuntu0.1 or later.
Where can I find more information about CVE-2018-20024?
You can find more information about CVE-2018-20024 on the GitHub page for LibVNC, as well as on the ICS-CERT advisory.