CVE-2018-7225
Last modified
CVE-2018-7225 is a vulnerability of currently unknown severity. An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.. EPSS estimates a 6.45% chance of exploitation in the next 30 days.
Description
An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libvncserver Project | Libvncserver | <= 0.9.11 |
| Debian | Debian Linux | 7.0 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 17.10 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.6 |
| Redhat | Enterprise Linux Server Eus | 7.5 |
| Redhat | Enterprise Linux Server Eus | 7.6 |
| Redhat | Enterprise Linux Server Tus | 7.6 |
| Redhat | Enterprise Linux Workstation | 7.0 |
References
- http://www.openwall.com/lists/oss-security/2018/02/18/1Exploit, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/103107Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1055Third Party Advisory
- https://github.com/LibVNC/libvncserver/issues/218Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00035.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3618-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4221Third Party Advisory
- http://www.openwall.com/lists/oss-security/2018/02/18/1Exploit, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/103107Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1055Third Party Advisory
- https://github.com/LibVNC/libvncserver/issues/218Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00035.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3618-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4221Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7225?
How severe is CVE-2018-7225?
How do I fix CVE-2018-7225?
Are you affected by CVE-2018-7225?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
