Learn about CVE-2018-20750, a heap out-of-bounds write vulnerability in libvncserver versions 0.9.12 and earlier, impacting systems. Find mitigation steps and necessary updates here.
A heap out-of-bounds write vulnerability in libvncserver versions 0.9.12 and earlier, with an incomplete fix from CVE-2018-15127.
Understanding CVE-2018-20750
What is CVE-2018-20750?
LibVNC through version 0.9.12 is susceptible to a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c.
The Impact of CVE-2018-20750
The incomplete fix for CVE-2018-15127 leaves systems vulnerable to potential exploitation through this heap out-of-bounds write vulnerability.
Technical Details of CVE-2018-20750
Vulnerability Description
The vulnerability exists in the file rfbserver.c of libvncserver versions 0.9.12 and prior, allowing for a heap out-of-bounds write.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates