#VU22957 Memory leak in LibVNCServer - CVE-2019-15681

 

#VU22957 Memory leak in LibVNCServer - CVE-2019-15681

Published: November 25, 2019 / Updated: June 30, 2020


Vulnerability identifier: #VU22957
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-15681
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
LibVNCServer
Software vendor:
LibVNC

Description

The vulnerability allows a remote attacker to gain access to sensitive information on the target system.

The vulnerability exists due memory leak in VNC server code. A remote attacker can read stack memory and disclose sensitive information.

Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR.


Remediation

Install update from vendor's website.

External links