CVE-2018-20023

Priority
Description
LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665:
Improper Initialization vulnerability in VNC Repeater client code that
allows attacker to read stack memory and can be abuse for information
disclosure. Combined with another vulnerability, it can be used to leak
stack memory layout and in bypassing ASLR
Assigned-to
mdeslaur
Package
Upstream:released (0.9.11+dfsg-1.2)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE (trusty was released [0.9.9+dfsg-1ubuntu1.4])
Ubuntu 16.04 LTS (Xenial Xerus):released (0.9.10+dfsg-3ubuntu0.16.04.3)
Ubuntu 18.04 LTS (Bionic Beaver):released (0.9.11+dfsg-1ubuntu1.1)
Ubuntu 18.10 (Cosmic Cuttlefish):released (0.9.11+dfsg-1.1ubuntu0.1)
Ubuntu 19.04 (Disco Dingo):not-affected (0.9.11+dfsg-1.2)
Ubuntu 19.10 (Eoan):not-affected (0.9.11+dfsg-1.2)
Patches:
Upstream:https://github.com/LibVNC/libvncserver/commit/8b06f835e259652b0ff026898014fc7297ade858
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):needs-triage
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 18.10 (Cosmic Cuttlefish):ignored (reached end-of-life)
Ubuntu 19.04 (Disco Dingo):needs-triage
Ubuntu 19.10 (Eoan):needs-triage
More Information

Updated: 2019-07-18 17:33:53 UTC (commit 649f8c6455205380e35ed054e9ea734222c716bb)