CVE-2018-6307 PUBLISHED

LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution.

EPSS 9.48% · 92.8th percentile

Risk Scores

EPSS Score
9.48%
92.8th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlibvncserver0, 0.9.11+dfsg-1, 0.9.11+dfsg-1ubuntu1
Ubuntu:14.04:LTSlibvncserver0, 0.9.9+dfsg-1, 0.9.9+dfsg-1ubuntu1
Ubuntu:16.04:LTSlibvncserver0, 0.9.10+dfsg-3, 0.9.10+dfsg-3build1

Timeline

References

Open in Interactive Console →