Bug 1671403 (CVE-2018-20749) - CVE-2018-20749 libvncserver: Heap out-of-bounds write in rfbserver.c in rfbProcessFileTransferReadBuffer() allows for potential code execution (Incomplete fix for CVE-2018-15127)
Summary: CVE-2018-20749 libvncserver: Heap out-of-bounds write in rfbserver.c in rfbPr...
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2018-20749
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1661115 1661116
Blocks: 1661105
TreeView+ depends on / blocked
 
Reported: 2019-01-31 14:29 UTC by Andrej Nemec
Modified: 2020-04-27 17:57 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in libvncserver. An incomplete fix for CVE-2018-15127 leaves open an out-of-bounds write vulnerability in code for the file transfer extension. This vulnerability can be remotely exploited. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Clone Of:
Environment:
Last Closed: 2019-06-10 10:47:08 UTC


Attachments (Terms of Use)

Description Andrej Nemec 2019-01-31 14:29:24 UTC
LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.

Upstream patch:

https://github.com/LibVNC/libvncserver/commit/15bb719c03cc70f14c36a843dcb16ed69b405707

Upstream issue:

https://github.com/LibVNC/libvncserver/issues/273

Comment 1 Andrej Nemec 2019-01-31 14:34:26 UTC
Created libvncserver tracking bugs for this issue:

Affects: epel-7 [bug 1661116]
Affects: fedora-all [bug 1661115]


Note You need to log in before you can comment on or make changes to this bug.