Heap use-after-free in LibVNCServer - CVE-2018-6307
Published: January 22, 2019
Vulnerability identifier: #VU17126
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6307
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to heap use-after-free error in server code of file transfer extension. A remote attacker can trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
LibVNCServer
libvncserver (Debian package)
Opensuse
libvncserver (Debian package)
Opensuse
How to mitigate CVE-2018-6307
Update to version 0.9.12.
LibVNCServer - update to 0.9.12
libvncserver (Debian package) - addressed in versions 0.9.9+dfsg2-6.1+deb8u5, 0.9.11+dfsg-1.3~deb9u1
libvncserver (Debian package) - addressed in versions 0.9.9+dfsg2-6.1+deb8u5, 0.9.11+dfsg-1.3~deb9u1