ISOMAN

CVE

CVE-2018-21247

An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00033.html
  2. http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00055.html
  3. http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00066.html
  4. https://cert-portal.siemens.com/productcert/pdf/ssa-390195.pdf
  5. https://github.com/LibVNC/libvncserver/compare/LibVNCServer-0.9.12...LibVNCServer-0.9.13
  6. https://github.com/LibVNC/libvncserver/issues/253
  7. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4F6FUH4EFK4NAP6GT4TQRTBKWIRCZLIY/
  8. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NVP7TJVYJDXDFRHVQ3ENEN3H354QPXEZ/
  9. http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00033.html
  10. http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00055.html
  11. http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00066.html
  12. https://cert-portal.siemens.com/productcert/pdf/ssa-390195.pdf
  13. https://github.com/LibVNC/libvncserver/compare/LibVNCServer-0.9.12...LibVNCServer-0.9.13
  14. https://github.com/LibVNC/libvncserver/issues/253
  15. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4F6FUH4EFK4NAP6GT4TQRTBKWIRCZLIY/
  16. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NVP7TJVYJDXDFRHVQ3ENEN3H354QPXEZ/