CVE-2018-20022 PUBLISHED

LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Improper Initialization vulnerability in VNC client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it can be used to leak stack memory layout and in bypassing ASLR

EPSS 6.18% · 90.8th percentile

Risk Scores

EPSS Score
6.18%
90.8th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlibvncserver0.9.9+dfsg-1, 0.9.9+dfsg-1ubuntu1, 0.9.9+dfsg-1ubuntu1.1
Ubuntu:18.04:LTSitalc*, *, 1:3.0.3+dfsg1-3
Ubuntu:16.04:LTSlibvncserver0, 0.9.10+dfsg-3, 0.9.10+dfsg-3ubuntu0.16.04.2
Ubuntu:16.04:LTStightvnc0, 1.3.10-0ubuntu2, 1.3.10-0ubuntu3
Ubuntu:16.04:LTSitalc0, *, 1:2.0.2+dfsg1-3
Ubuntu:25.10tightvnc1:1.3.10-9, 0, 1:1.3.10-10
Ubuntu:16.04:LTSssvnc0, 1.0.29-2build1
Ubuntu:18.04:LTSssvnc0, 1.0.29-3, 1.0.29-3build1
Ubuntu:18.04:LTSlibvncserver0.9.11+dfsg-1, 0.9.11+dfsg-1ubuntu1, 0
Ubuntu:Pro:14.04:LTStightvnc1.3.9-6.4, 1.3.9-6.4ubuntu1, 0
Ubuntu:18.04:LTStightvnc1.3.10-0ubuntu3, 0, 1.3.10-0ubuntu4
Ubuntu:22.04:LTStightvnc0, 1:1.3.10-3, *
Ubuntu:20.04:LTStightvnc0, 1.3.10-0ubuntu5
Ubuntu:24.04:LTStightvnc1:1.3.10-8, *, 1:1.3.10-7build2

Timeline

References

Open in Interactive Console →