Integer overflow in LibVNCServer - CVE-2018-7225

 

Integer overflow in LibVNCServer - CVE-2018-7225

Published: March 21, 2018 / Updated: November 25, 2019


Vulnerability identifier: #VU11221
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7225
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The weakness exists in the rfbProcessClientNormalMessage() function due to integer overflow. A remote attacker can trigger memory corruption and gain access to potentially sensitive information.


Affected software

LibVNCServer
Debian Linux
Fedora
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
SUSE Linux
Ubuntu
libvncserver (Alpine package)
libvncserver
guacamole-server
italc-client (Ubuntu package)
italc-master (Ubuntu package)
libitalccore (Ubuntu package)

How to mitigate CVE-2018-7225

Install update from vendor's website.

LibVNCServer - update to 0.9.12
libvncserver (Alpine package) - addressed in versions 0.9.11-r1, 0.9.11-r2
libvncserver - addressed in versions 0.9.9-0.12.el7, 0.9.11-3.fc26, 0.9.11-5.fc27, 0.9.11-6.fc28
guacamole-server - update to 0.9.14-1.el7
italc-client (Ubuntu package) - update to 1:3.0.3+dfsg1-3ubuntu0.1
italc-master (Ubuntu package) - update to 1:3.0.3+dfsg1-3ubuntu0.1
libitalccore (Ubuntu package) - update to 1:3.0.3+dfsg1-3ubuntu0.1

External References

Related Security Bulletins