CVE-2019-15681: High severity Libvnc Project Libvncserver vulnerability
Last updated 11 July 2025
Other sources
LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appear to be exploitable via network connectivity. These vulnerabilities have been fixed in commit d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6 - Upgrade
Upgrade
debian/tightvncto a version that resolves this vulnerability.Fixed in 1:1.3.10-3Fixed in 1:1.3.10-7Fixed in 1:1.3.10-9Fixed in 1:1.3.10-11 - Upgrade
Upgrade
debian/vinoto a version that resolves this vulnerability.Fixed in 3.22.0-6 - Upgrade
Upgrade
LibVNCto a version that resolves this vulnerability.Patch d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a
Event History
Frequently Asked Questions
What is CVE-2019-15681?
CVE-2019-15681 is a vulnerability in LibVNC server code that allows an attacker to read stack memory and potentially leak sensitive information.
How severe is CVE-2019-15681?
CVE-2019-15681 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2019-15681?
CVE-2019-15681 affects libvncserver versions 0.9.11+dfsg-1ubuntu1.2, 0.9.11+dfsg-1.3ubuntu0.1, 0.9.10+dfsg-3ubuntu0.16.04.4, tightvnc version 1.3.9-6.5+, italc versions 1:3.0.3+dfsg1-3ubuntu0.1, 1:3.0.3+dfsg1-1+, 1:2.0.2+dfsg1-2+, 1:2.0.2+dfsg1-4ubuntu0.1, and vino versions 3.22.0-3ubuntu1.1, 3.22.0-5ubuntu2.1, 3.22.0-6ubuntu1, 3.8.1-0ubuntu9.3, 3.22.0-6ubuntu1.
How can I fix CVE-2019-15681?
To fix CVE-2019-15681, update to libvncserver version 0.9.11+dfsg-1ubuntu1.2, 0.9.11+dfsg-1.3ubuntu0.1, 0.9.10+dfsg-3ubuntu0.16.04.4, tightvnc version 1.3.9-6.5+, italc versions 1:3.0.3+dfsg1-3ubuntu0.1, 1:3.0.3+dfsg1-1+, 1:2.0.2+dfsg1-2+, 1:2.0.2+dfsg1-4ubuntu0.1, or vino versions 3.22.0-3ubuntu1.1, 3.22.0-5ubuntu2.1, 3.22.0-6ubuntu1, 3.8.1-0ubuntu9.3, 3.22.0-6ubuntu1.
Can CVE-2019-15681 bypass ASLR?
CVE-2019-15681 can be combined with another vulnerability to bypass ASLR.