First published: Thu Jan 31 2019(Updated: )
It was discovered that LibVNCServer incorrectly handled certain operations. A remote attacker able to connect to applications using LibVNCServer could possibly use this issue to obtain sensitive information, cause a denial of service, or execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libvncclient1 | <0.9.11+dfsg-1.1ubuntu0.1 | 0.9.11+dfsg-1.1ubuntu0.1 |
=18.10 | ||
All of | ||
ubuntu/libvncserver1 | <0.9.11+dfsg-1.1ubuntu0.1 | 0.9.11+dfsg-1.1ubuntu0.1 |
=18.10 | ||
All of | ||
ubuntu/libvncclient1 | <0.9.11+dfsg-1ubuntu1.1 | 0.9.11+dfsg-1ubuntu1.1 |
=18.04 | ||
All of | ||
ubuntu/libvncserver1 | <0.9.11+dfsg-1ubuntu1.1 | 0.9.11+dfsg-1ubuntu1.1 |
=18.04 | ||
All of | ||
ubuntu/libvncclient1 | <0.9.10+dfsg-3ubuntu0.16.04.3 | 0.9.10+dfsg-3ubuntu0.16.04.3 |
=16.04 | ||
All of | ||
ubuntu/libvncserver1 | <0.9.10+dfsg-3ubuntu0.16.04.3 | 0.9.10+dfsg-3ubuntu0.16.04.3 |
=16.04 | ||
All of | ||
ubuntu/libvncserver0 | <0.9.9+dfsg-1ubuntu1.4 | 0.9.9+dfsg-1ubuntu1.4 |
=14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability ID for the LibVNCServer vulnerabilities is USN-3877-1.
The LibVNCServer vulnerabilities can allow a remote attacker to obtain sensitive information, cause a denial of service, or execute arbitrary code.
The LibVNCServer vulnerabilities affect libvncclient1, libvncserver1, and libvncserver0 versions 0.9.11+dfsg-1.1ubuntu0.1, 0.9.11+dfsg-1ubuntu1.1, 0.9.10+dfsg-3ubuntu0.16.04.3, and 0.9.9+dfsg-1ubuntu1.4 on Ubuntu 18.10, 18.04, 16.04, and 14.04.
A remote attacker able to connect to applications using LibVNCServer can exploit these vulnerabilities to perform various malicious activities.
To fix the LibVNCServer vulnerabilities, update the libvncclient1, libvncserver1, and libvncserver0 packages to the specified remedy versions for your Ubuntu version.