CVE-2018-7225

critical
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.

References

http://www.openwall.com/lists/oss-security/2018/02/18/1

http://www.securityfocus.com/bid/103107

https://access.redhat.com/errata/RHSA-2018:1055

https://github.com/LibVNC/libvncserver/issues/218

https://lists.debian.org/debian-lts-announce/2018/03/msg00035.html

https://lists.debian.org/debian-lts-announce/2019/10/msg00042.html

https://lists.debian.org/debian-lts-announce/2019/11/msg00032.html

https://lists.debian.org/debian-lts-announce/2019/12/msg00028.html

https://security.gentoo.org/glsa/201908-05

https://usn.ubuntu.com/3618-1/

https://usn.ubuntu.com/4547-1/

https://usn.ubuntu.com/4573-1/

https://usn.ubuntu.com/4587-1/

https://www.debian.org/security/2018/dsa-4221

Details

Source: MITRE

Published: 2018-02-19

Updated: 2020-10-23

Type: CWE-190

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 3.9

Severity: CRITICAL

Tenable Plugins

View all (24 total)

IDNameProductFamilySeverity
141545Ubuntu 16.04 LTS : iTALC vulnerabilities (USN-4587-1)NessusUbuntu Local Security Checks
critical
141301Ubuntu 16.04 LTS / 18.04 LTS / 20.04 LTS : Vino vulnerabilities (USN-4573-1)NessusUbuntu Local Security Checks
critical
140920Ubuntu 18.04 LTS : iTALC vulnerabilities (USN-4547-1)NessusUbuntu Local Security Checks
critical
132345Debian DLA-2045-1 : tightvnc security updateNessusDebian Local Security Checks
critical
131432Debian DLA-2014-1 : vino security updateNessusDebian Local Security Checks
critical
130408Debian DLA-1979-1 : italc security updateNessusDebian Local Security Checks
critical
127563GLSA-201908-05 : LibVNCServer: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
127237NewStart CGSL CORE 5.04 / MAIN 5.04 : libvncserver Multiple Vulnerabilities (NS-SA-2019-0052)NessusNewStart CGSL Local Security Checks
critical
120355Fedora 28 : libvncserver (2018-390001d1c7)NessusFedora Local Security Checks
critical
110828EulerOS 2.0 SP3 : libvncserver (EulerOS-SA-2018-1176)NessusHuawei Local Security Checks
critical
110420Debian DSA-4221-1 : libvncserver - security updateNessusDebian Local Security Checks
critical
110235CentOS 7 : libvncserver (CESA-2018:1055)NessusCentOS Local Security Checks
critical
110143EulerOS 2.0 SP1 : libvncserver (EulerOS-SA-2018-1139)NessusHuawei Local Security Checks
critical
109691Amazon Linux 2 : libvncserver (ALAS-2018-1012)NessusAmazon Linux Local Security Checks
critical
109451Scientific Linux Security Update : libvncserver on SL7.x x86_64 (20180410)NessusScientific Linux Local Security Checks
critical
109153Oracle Linux 7 : libvncserver (ELSA-2018-1055)NessusOracle Linux Local Security Checks
critical
108994RHEL 7 : libvncserver (RHSA-2018:1055)NessusRed Hat Local Security Checks
critical
108872SUSE SLES11 Security Update : LibVNCServer (SUSE-SU-2018:0875-1)NessusSuSE Local Security Checks
critical
108841Ubuntu 14.04 LTS / 16.04 LTS / 17.10 : libvncserver vulnerability (USN-3618-1)NessusUbuntu Local Security Checks
critical
108818Fedora 26 : libvncserver (2018-43541091ab)NessusFedora Local Security Checks
critical
108766Debian DLA-1332-1 : libvncserver security updateNessusDebian Local Security Checks
critical
108743openSUSE Security Update : LibVNCServer (openSUSE-2018-326)NessusSuSE Local Security Checks
critical
108685SUSE SLES12 Security Update : LibVNCServer (SUSE-SU-2018:0830-1)NessusSuSE Local Security Checks
critical
108669Fedora 27 : libvncserver (2018-4897772a43)NessusFedora Local Security Checks
critical