CVE-2018-7225: Integer Overflow
An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6 - Upgrade
Upgrade
debian/tightvncto a version that resolves this vulnerability.Fixed in 1:1.3.10-3Fixed in 1:1.3.10-7Fixed in 1:1.3.10-9Fixed in 1:1.3.10-11 - Upgrade
Upgrade
debian/vinoto a version that resolves this vulnerability.Fixed in 3.22.0-6
Event History
Frequently Asked Questions
What is CVE-2018-7225?
CVE-2018-7225 is a vulnerability in LibVNCServer that allows access to uninitialized and potentially sensitive data.
What is the severity of CVE-2018-7225?
CVE-2018-7225 has a severity rating of 9.8 (critical).
How does CVE-2018-7225 impact affected software?
CVE-2018-7225 can lead to access to uninitialized and potentially sensitive data or unspecified other impact.
Where can I find more information about CVE-2018-7225?
You can find more information about CVE-2018-7225 on the GitHub page and the Debian security tracker.
What is the Common Weakness Enumeration (CWE) associated with CVE-2018-7225?
The Common Weakness Enumeration (CWE) associated with CVE-2018-7225 is CWE-190.