CVE-2018-20748: Critical severity Libvnc Project Libvncserver vulnerability
Last updated 11 July 2025
Other sources
LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6 - Upgrade
Upgrade
debian/veyonto a version that resolves this vulnerability.Fixed in 4.5.3+repack1-1Fixed in 4.7.5+repack1-1Fixed in 4.9.5+repack1-2Fixed in 4.9.7+repack1-1.1 - Upgrade
Upgrade
LibVNCto a version that resolves this vulnerability.Fixed in 0.9.12
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-20748.
What is the severity of CVE-2018-20748?
The severity of CVE-2018-20748 is critical, with a severity value of 9.8.
Which software is affected by CVE-2018-20748?
The software affected by CVE-2018-20748 includes LibVNC before version 0.9.12, italc package on Ubuntu, libvncserver package on Ubuntu and Debian, and veyon package on Debian.
What is the fix for CVE-2018-20748?
The fix for CVE-2018-20748 can be found in the following commits: c5ba3fee85a7ecbbca1df5ffd46d32b92757bc2a, e34bcbb759ca5bef85809967a268fdf214c1ad2c, and c2c4b81e6cb3b485fb1ec7ba9e7defeb889f6ba7.
What is the Common Vulnerabilities and Exposures (CVE) index?
The Common Vulnerabilities and Exposures (CVE) index is a system used to uniquely identify vulnerabilities in software and systems. It provides a standardized naming scheme for vulnerabilities and is widely used in the cybersecurity industry.