CVE-2017-18922 PUBLISHED

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

EPSS 4.78% · 89.4th percentile

Risk Scores

EPSS Score
4.78%
89.4th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlibvncserver0.9.11+dfsg-1.3, 0.9.12+dfsg-3ubuntu3, 0.9.12+dfsg-6
Ubuntu:24.04:LTSveyon4.7.5+repack1-1ubuntu5, 4.7.5+repack1-1ubuntu4, 4.7.5+repack1-1ubuntu3
Ubuntu:20.04:LTSveyon0, 4.3.1+repack1-2build2, 4.3.1+repack1-2build1
Ubuntu:25.10veyon4.9.7+repack1-1, 0, 4.7.5+repack1-1ubuntu6
Ubuntu:16.04:LTSlibvncserver0, 0.9.10+dfsg-3ubuntu0.16.04.3, 0.9.10+dfsg-3ubuntu0.16.04.1
Ubuntu:22.04:LTSveyon0, 4.5.3+repack1-1build1, 4.5.3+repack1-1build2
Ubuntu:14.04:LTSx11vnc0.9.13-1.1, 0
Ubuntu:18.04:LTSlibvncserver0.9.11+dfsg-1, 0.9.11+dfsg-1ubuntu1.1, 0.9.11+dfsg-1ubuntu1

Timeline

References

Open in Interactive Console →