CVE-2018-6307: Use After Free
Last updated 25 August 2025
Other sources
LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6 - Upgrade
Upgrade
LibVNCto a version that resolves this vulnerability.Fixed in before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10bPatch ca2a5ac02fbbadd0a21fabba779c1ea69173d10b
Event History
Frequently Asked Questions
What is CVE-2018-6307?
CVE-2018-6307 is a vulnerability in LibVNC that allows remote code execution.
What is the severity of CVE-2018-6307?
The severity of CVE-2018-6307 is high, with a CVSS score of 8.1.
How does CVE-2018-6307 affect LibVNC?
CVE-2018-6307 affects LibVNC by causing a use-after-free vulnerability in the server code of the file transfer extension.
What is the remedy for CVE-2018-6307 in Debian?
The remedy for CVE-2018-6307 in Debian is to upgrade to version 0.9.11+dfsg-1.3+deb10u4 or later.
What is the remedy for CVE-2018-6307 in Ubuntu?
The remedy for CVE-2018-6307 in Ubuntu is to upgrade to version 0.9.11+dfsg-1ubuntu1.1 or later.