Heap use-after-free in LibVNCServer - CVE-2018-6307

 

Heap use-after-free in LibVNCServer - CVE-2018-6307

Published: January 22, 2019


Vulnerability identifier: #VU17126
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6307
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to heap use-after-free error in server code of file transfer extension. A remote attacker can trigger memory corruption and execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.


Affected software

LibVNCServer
libvncserver (Debian package)
Opensuse

How to mitigate CVE-2018-6307

Update to version 0.9.12.

LibVNCServer - update to 0.9.12
libvncserver (Debian package) - addressed in versions 0.9.9+dfsg2-6.1+deb8u5, 0.9.11+dfsg-1.3~deb9u1

External References

Related Security Bulletins