CVE-2018-7225
Last modified
CVE-2018-7225 is a vulnerability of currently unknown severity. An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.. EPSS estimates a 6.45% chance of exploitation in the next 30 days.
Description
An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libvncserver Project | Libvncserver | <= 0.9.11 |
| Debian | Debian Linux | 7.0 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 17.10 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.6 |
| Redhat | Enterprise Linux Server Eus | 7.5 |
| Redhat | Enterprise Linux Server Eus | 7.6 |
| Redhat | Enterprise Linux Server Tus | 7.6 |
| Redhat | Enterprise Linux Workstation | 7.0 |
References
- http://www.openwall.com/lists/oss-security/2018/02/18/1Exploit, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/103107Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1055Third Party Advisory
- https://github.com/LibVNC/libvncserver/issues/218Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00035.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3618-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4221Third Party Advisory
- http://www.openwall.com/lists/oss-security/2018/02/18/1Exploit, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/103107Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1055Third Party Advisory
- https://github.com/LibVNC/libvncserver/issues/218Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00035.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3618-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4221Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7225?
How severe is CVE-2018-7225?
How do I fix CVE-2018-7225?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-7212An issue was discovered in rack-protection/lib/rack/protecti…
- CVE-2018-7213The Password Manager Extension in Abine Blur 7.8.242* before…
- CVE-2018-7216Cross-site request forgery (CSRF) vulnerability in esop/tool…
- CVE-2018-7217In Bravo Tejari Procurement Portal, uploaded files are not p…
- CVE-2018-7218The AppFirewall functionality in Citrix NetScaler Applicatio…
- CVE-2018-7219application/admin/controller/Admin.php in NoneCms 1.3.0 has …
- CVE-2018-7226An issue was discovered in vcSetXCutTextProc() in VNConsole.…
- CVE-2018-7227A vulnerability exists in Schneider Electric's Pelco Sarix P…5.3
- CVE-2018-7228A vulnerability exists in Schneider Electric's Pelco Sarix P…9.8
- CVE-2018-7229A vulnerability exists in Schneider Electric's Pelco Sarix P…9.8
- CVE-2018-7230A XML external entity (XXE) vulnerability exists in the impo…8.8
- CVE-2018-7231A vulnerability exists in Schneider Electric's Pelco Sarix P…9.8
Are you affected by CVE-2018-7225?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
