CVE-2018-20750: Critical severity Libvnc Project Libvncserver vulnerability
Last updated 25 August 2025
Other sources
LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6 - Upgrade
Upgrade
LibVNCto a version that resolves this vulnerability.Patch CVE-2018-15127
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20750?
The severity of CVE-2018-20750 is critical with a CVSS score of 9.8.
How does CVE-2018-20750 affect LibVNC?
CVE-2018-20750 affects LibVNC through version 0.9.12.
What is the vulnerability description of CVE-2018-20750?
CVE-2018-20750 is a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c in LibVNC.
Which software is affected by CVE-2018-20750?
The following software versions are affected by CVE-2018-20750: italc 1:3.0.3+dfsg1-3ubuntu0.1, italc 1:3.0.3+dfsg1-1+ / 1:2.0.2+dfsg1-2+, italc 1:2.0.2+dfsg1-4ubuntu0.1, libvncserver 0.9.11+dfsg-1ubuntu1.1, libvncserver 0.9.11+dfsg-1.1ubuntu0.1, libvncserver 0.9.9+dfsg-1ubuntu1.4, libvncserver 0.9.11+dfsg-1.3, libvncserver 0.9.10+dfsg-3ubuntu0.16.04.3, libvncserver 0.9.11+dfsg-1.3+deb10u4 / 0.9.11+dfsg-1.3+deb10u5 / 0.9.13+dfsg-2+deb11u1 / 0.9.14+dfsg-1.
How do I fix the CVE-2018-20750 vulnerability?
To fix the CVE-2018-20750 vulnerability, update to the following versions: italc 1:3.0.3+dfsg1-3ubuntu0.1, italc 1:3.0.3+dfsg1-1+ / 1:2.0.2+dfsg1-2+, italc 1:2.0.2+dfsg1-4ubuntu0.1, libvncserver 0.9.11+dfsg-1ubuntu1.1, libvncserver 0.9.11+dfsg-1.1ubuntu0.1, libvncserver 0.9.9+dfsg-1ubuntu1.4, libvncserver 0.9.11+dfsg-1.3, libvncserver 0.9.10+dfsg-3ubuntu0.16.04.3, libvncserver 0.9.11+dfsg-1.3+deb10u4 / 0.9.11+dfsg-1.3+deb10u5 / 0.9.13+dfsg-2+deb11u1 / 0.9.14+dfsg-1.