CVE-2018-20023

Priority
Description
LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665:
Improper Initialization vulnerability in VNC Repeater client code that
allows attacker to read stack memory and can be abuse for information
disclosure. Combined with another vulnerability, it can be used to leak
stack memory layout and in bypassing ASLR
Assigned-to
mdeslaur
Package
Upstream:released (0.9.11+dfsg-1.2)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):released (0.9.9+dfsg-1ubuntu1.4)
Ubuntu 16.04 LTS (Xenial Xerus):released (0.9.10+dfsg-3ubuntu0.16.04.3)
Ubuntu 18.04 LTS (Bionic Beaver):released (0.9.11+dfsg-1ubuntu1.1)
Ubuntu 18.10 (Cosmic Cuttlefish):released (0.9.11+dfsg-1.1ubuntu0.1)
Ubuntu 19.04 (Disco Dingo):not-affected (0.9.11+dfsg-1.2)
Patches:
Upstream:https://github.com/LibVNC/libvncserver/commit/8b06f835e259652b0ff026898014fc7297ade858
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):needs-triage
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 18.10 (Cosmic Cuttlefish):needs-triage
Ubuntu 19.04 (Disco Dingo):needs-triage
More Information

Updated: 2019-01-31 21:14:21 UTC (commit 2e0d8cdedda47ef96c2828bef37192f5d5eeb000)