CVE-2018-7225
libvncserver - security update
9.8
CRITICAL
CVSS 3.1
EPSS 3.3%
Description
An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.
How to fix CVE-2018-7225
To remediate CVE-2018-7225, upgrade the affected package to a fixed version below.
- —upgrade to 0.9.11-r2 or later
- —upgrade to 0.9.11+dfsg-1.1 or later
- —upgrade to 0.9.9+dfsg-1+deb7u3 or later
- —upgrade to 0.9.9+dfsg2-6.1+deb8u3 or later
- —upgrade to 1:1.3.9-9.1 or later
- —upgrade to 3.22.0-6 or later
Is CVE-2018-7225 being exploited?
Low — EPSS is 3.3%, meaning exploitation activity has not been observed at scale.
Affected packages (6)
- from 0, < 0.9.11-r2
- from 0, < 0.9.11+dfsg-1.1
- from 0, < 0.9.9+dfsg-1+deb7u3
- from 0, < 0.9.9+dfsg2-6.1+deb8u3
- from 0, < 1:1.3.9-9.1
- from 0, < 3.22.0-6
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |