CVE-2018-20023

Priority
Description
LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665:
Improper Initialization vulnerability in VNC Repeater client code that
allows attacker to read stack memory and can be abuse for information
disclosure. Combined with another vulnerability, it can be used to leak
stack memory layout and in bypassing ASLR
Assigned-to
mdeslaur
Notes
Package
Upstream:released (0.9.11+dfsg-1.2)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE (trusty was released [0.9.9+dfsg-1ubuntu1.4])
Ubuntu 16.04 LTS (Xenial Xerus):released (0.9.10+dfsg-3ubuntu0.16.04.3)
Ubuntu 18.04 LTS (Bionic Beaver):released (0.9.11+dfsg-1ubuntu1.1)
Patches:
Upstream:https://github.com/LibVNC/libvncserver/commit/8b06f835e259652b0ff026898014fc7297ade858
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):not-affected (uses shared libvnc)
Ubuntu 16.04 LTS (Xenial Xerus):not-affected (uses shared libvnc)
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (uses shared libvnc)
More Information

Updated: 2020-07-28 20:04:46 UTC (commit d26b6ca9f5b3adb89bb036ce73ae7dab894935ec)