CVE-2017-18922

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
libvncserver_projectlibvncserver
𝑥
< 0.9.12
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
canonicalubuntu_linux
19.10
canonicalubuntu_linux
20.04
opensuseleap
15.1
opensuseleap
15.2
siemenssimatic_itc1500_firmware
3.0.0.0 ≤
𝑥
< 3.2.1.0
siemenssimatic_itc1500_pro_firmware
3.0.0.0 ≤
𝑥
< 3.2.1.0
siemenssimatic_itc1900_firmware
3.0.0.0 ≤
𝑥
< 3.2.1.0
siemenssimatic_itc1900_pro_firmware
3.0.0.0 ≤
𝑥
< 3.2.1.0
siemenssimatic_itc2200_firmware
3.0.0.0 ≤
𝑥
< 3.2.1.0
siemenssimatic_itc2200_pro_firmware
3.0.0.0 ≤
𝑥
< 3.2.1.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libvncserver
bookworm
0.9.14+dfsg-1
fixed
bullseye
0.9.13+dfsg-2+deb11u1
fixed
buster
ignored
sid
0.9.14+dfsg-1
fixed
stretch
ignored
trixie
0.9.14+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libvncserver
bionic
Fixed 0.9.11+dfsg-1ubuntu1.2
released
eoan
Fixed 0.9.11+dfsg-1.3ubuntu0.1
released
focal
Fixed 0.9.12+dfsg-9ubuntu0.1
released
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
dne
xenial
Fixed 0.9.10+dfsg-3ubuntu0.16.04.4
released
veyon
bionic
dne
eoan
ignored
focal
needs-triage
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needs-triage
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needs-triage
trusty
dne
xenial
dne
x11vnc
bionic
needs-triage
eoan
ignored
focal
needs-triage
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needs-triage
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needs-triage
trusty
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libvncclient0
suse enterprise desktop 15 SP2
0.9.10-4.22.1
fixed
suse enterprise desktop 15 SP3
0.9.10-4.22.1
fixed
suse enterprise sap 12 SP2
0.9.9-17.31.1
fixed
suse enterprise sap 12 SP3
0.9.9-17.31.1
fixed
suse enterprise sap 12 SP4
0.9.9-17.31.1
fixed
suse enterprise sap 12 SP5
0.9.9-17.31.1
fixed
suse enterprise sap 15 SP2
0.9.10-4.22.1
fixed
suse enterprise sap 15 SP3
0.9.10-4.22.1
fixed
suse enterprise server 12 SP2
0.9.9-17.31.1
fixed
suse enterprise server 12 SP3
0.9.9-17.31.1
fixed
suse enterprise server 12 SP4
0.9.9-17.31.1
fixed
suse enterprise server 12 SP5
0.9.9-17.31.1
fixed
suse enterprise server 15 SP2
0.9.10-4.22.1
fixed
suse enterprise server 15 SP3
0.9.10-4.22.1
fixed
suse enterprise workstation 15 SP2
0.9.10-4.22.1
fixed
suse enterprise workstation 15 SP3
0.9.10-4.22.1
fixed
libvncclient1
suse enterprise desktop 15 SP4
0.9.13-150400.1.9
fixed
suse enterprise sap 15 SP4
0.9.13-150400.1.9
fixed
suse enterprise server 15 SP4
0.9.13-150400.1.9
fixed
suse enterprise workstation 15 SP4
0.9.13-150400.1.9
fixed
libvncserver0
suse enterprise desktop 15 SP2
0.9.10-4.22.1
fixed
suse enterprise desktop 15 SP3
0.9.10-4.22.1
fixed
suse enterprise sap 12 SP2
0.9.9-17.31.1
fixed
suse enterprise sap 12 SP3
0.9.9-17.31.1
fixed
suse enterprise sap 12 SP4
0.9.9-17.31.1
fixed
suse enterprise sap 12 SP5
0.9.9-17.31.1
fixed
suse enterprise sap 15 SP2
0.9.10-4.22.1
fixed
suse enterprise sap 15 SP3
0.9.10-4.22.1
fixed
suse enterprise server 12 SP2
0.9.9-17.31.1
fixed
suse enterprise server 12 SP3
0.9.9-17.31.1
fixed
suse enterprise server 12 SP4
0.9.9-17.31.1
fixed
suse enterprise server 12 SP5
0.9.9-17.31.1
fixed
suse enterprise server 15 SP2
0.9.10-4.22.1
fixed
suse enterprise server 15 SP3
0.9.10-4.22.1
fixed
suse enterprise workstation 15 SP2
0.9.10-4.22.1
fixed
suse enterprise workstation 15 SP3
0.9.10-4.22.1
fixed
libvncserver1
suse enterprise desktop 15 SP4
0.9.13-150400.1.9
fixed
suse enterprise sap 15 SP4
0.9.13-150400.1.9
fixed
suse enterprise server 15 SP4
0.9.13-150400.1.9
fixed
suse enterprise workstation 15 SP4
0.9.13-150400.1.9
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libvncserver
RHEL 7
0:0.9.9-14.el7_8.1
fixed
RHEL 8
0:0.9.11-15.el8_2.1
fixed
RHEL 8.1 E4S
0:0.9.11-9.el8_1.3
fixed
RHEL 8.1 EUS
0:0.9.11-9.el8_1.3
fixed
RHEL 8.2 AUS
0:0.9.11-15.el8_2.1
fixed
RHEL 8.2 E4S
0:0.9.11-15.el8_2.1
fixed
RHEL 8.2 EUS
0:0.9.11-15.el8_2.1
fixed
RHEL 8.2 TUS
0:0.9.11-15.el8_2.1
fixed
libvncserver-devel
RHEL 7
0:0.9.9-14.el7_8.1
fixed
RHEL 8
0:0.9.11-15.el8_2.1
fixed
RHEL 8.1 E4S
0:0.9.11-9.el8_1.3
fixed
RHEL 8.1 EUS
0:0.9.11-9.el8_1.3
fixed
RHEL 8.2 AUS
0:0.9.11-15.el8_2.1
fixed
RHEL 8.2 E4S
0:0.9.11-15.el8_2.1
fixed
RHEL 8.2 EUS
0:0.9.11-15.el8_2.1
fixed
RHEL 8.2 TUS
0:0.9.11-15.el8_2.1
fixed
References