CVE-2018-21247 PUBLISHED

An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.

EPSS 1.48% · 80.9th percentile

Risk Scores

EPSS Score
1.48%
80.9th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSx11vnc0, 0.9.13-1.1
Ubuntu:Pro:18.04:LTSx11vnc0, 0.9.13-3ubuntu0.1~esm1, 0.9.13-3
Ubuntu:20.04:LTSveyon4.2.4+repack1-2, 0, 4.3.1+repack1-2build2
Ubuntu:24.04:LTSveyon4.7.5+repack1-1build2, 4.7.5+repack1-1ubuntu5, 4.7.5+repack1-1ubuntu4
Ubuntu:Pro:20.04:LTSx11vnc0.9.16-3, 0, 0.9.13-6
Ubuntu:25.10veyon4.9.7+repack1-1, 4.7.5+repack1-1ubuntu7, 4.7.5+repack1-1ubuntu6
Ubuntu:16.04:LTSlibvncserver0.9.10+dfsg-3ubuntu0.16.04.1, 0.9.10+dfsg-3ubuntu0.16.04.2, 0.9.10+dfsg-3ubuntu0.16.04.3
Ubuntu:Pro:16.04:LTSx11vnc0.9.13-1.2ubuntu0.1~esm1, 0.9.13-1.2build1, 0
Ubuntu:22.04:LTSveyon4.5.3+repack1-1build2, 0, 4.5.3+repack1-1build1
Ubuntu:18.04:LTSlibvncserver0.9.11+dfsg-1ubuntu1.2, 0.9.11+dfsg-1ubuntu1, 0.9.11+dfsg-1
Ubuntu:20.04:LTSlibvncserver0.9.12+dfsg-9, 0.9.12+dfsg-8, 0.9.12+dfsg-7

Timeline

References

Open in Interactive Console →