CVE-2018-21247: High severity libvncserver vulnerability
An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-21247.
What is the severity level of CVE-2018-21247?
The severity level of CVE-2018-21247 is high (7.5).
What is the affected software?
The affected software includes LibVNCServer versions up to and including 0.9.12, Canonical Ubuntu Linux 14.04, 16.04, and 18.04, Debian Debian Linux 8.0 and 9.0, and Siemens Simatic Itc1500/Itc1500 Pro/Itc1900/Itc1900 Pro/Itc2200/Itc2200 Pro firmware versions up to and including 3.2.1.0.
What is the description of this vulnerability?
This vulnerability is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function of LibVNCServer before 0.9.13.
Are there any references available for CVE-2018-21247?
Yes, you can find references regarding CVE-2018-21247 at the following links: [Link 1](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00033.html), [Link 2](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00055.html), [Link 3](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00066.html).