Bug 1671403 (CVE-2018-20749) - CVE-2018-20749 libvncserver: Heap out-of-bounds write in rfbserver.c in rfbProcessFileTransferReadBuffer() allows for potential code execution (Incomplete fix for CVE-2018-15127)
Summary: CVE-2018-20749 libvncserver: Heap out-of-bounds write in rfbserver.c in rfbPr...
Alias: CVE-2018-20749
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 1661115 1661116
Blocks: 1661105
TreeView+ depends on / blocked
Reported: 2019-01-31 14:29 UTC by Andrej Nemec
Modified: 2020-04-27 17:57 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in libvncserver. An incomplete fix for CVE-2018-15127 leaves open an out-of-bounds write vulnerability in code for the file transfer extension. This vulnerability can be remotely exploited. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Clone Of:
Last Closed: 2019-06-10 10:47:08 UTC

Attachments (Terms of Use)

Description Andrej Nemec 2019-01-31 14:29:24 UTC
LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.

Upstream patch:


Upstream issue:


Comment 1 Andrej Nemec 2019-01-31 14:34:26 UTC
Created libvncserver tracking bugs for this issue:

Affects: epel-7 [bug 1661116]
Affects: fedora-all [bug 1661115]

Note You need to log in before you can comment on or make changes to this bug.