UBUNTU-CVE-2018-7225
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-7225
UBUNTU-CVE-2018-7225
Summary:
Details: An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.
References: https://ubuntu.com/security/CVE-2018-7225, http://www.openwall.com/lists/oss-security/2018/02/18/1, https://ubuntu.com/security/notices/USN-3618-1, https://ubuntu.com/security/notices/USN-4547-1, https://ubuntu.com/security/notices/USN-4573-1, https://ubuntu.com/security/notices/USN-4587-1, https://www.cve.org/CVERecord?id=CVE-2018-7225
Affected packages
Package
Name: libvncserver
Purl: pkg:deb/ubuntu/libvncserver?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
