CVE-2018-20749: Critical severity Libvnc Project Libvncserver vulnerability
Last updated 25 August 2025
Other sources
LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6 - Upgrade
Upgrade
LibVNCto a version that resolves this vulnerability.Fixed in 0.9.12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2018-15127
Event History
Frequently Asked Questions
What is CVE-2018-20749?
CVE-2018-20749 is a heap out-of-bounds write vulnerability in LibVNC before 0.9.12.
What is the severity of CVE-2018-20749?
The severity of CVE-2018-20749 is critical with a CVSS score of 9.8.
How does CVE-2018-20749 affect LibVNC?
CVE-2018-20749 affects LibVNC before version 0.9.12.
How can I fix CVE-2018-20749?
To fix CVE-2018-20749, you should update LibVNC to version 0.9.12 or later.
Where can I find more information about CVE-2018-20749?
You can find more information about CVE-2018-20749 at the following references: [1] [2] [3].