CVE-2017-18922
libvncserver: websocket decoding buffer overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.
Se detectó que el archivo websockets.c en LibVNCServer versiones anteriores a 0.9.12, no decodificaba apropiadamente determinados tramas de WebSocket. Un atacante malicioso podría explotar esto mediante el envío de tramas de WebSocket especialmente diseñadas hacia un servidor, causando un desbordamiento del búfer en la región heap de la memoria
A flaw was found in libvncserver. A heap-based buffer overflow within the websocket decoding functionality is possible, which can lead to exploitation by a malicious attacker to overwrite a function pointer. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-06-30 CVE Reserved
- 2020-06-30 CVE Published
- 2023-05-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-122: Heap-based Buffer Overflow
- CWE-787: Out-of-bounds Write
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2020/06/30/3 | Mailing List | |
https://www.openwall.com/lists/oss-security/2020/06/30/2 | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-390195.pdf | 2023-11-07 | |
https://github.com/LibVNC/libvncserver/commit/aac95a9dcf4bbba87b76c72706c3221a842ca433 | 2023-11-07 | |
https://usn.ubuntu.com/4407-1 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Simatic Itc1500 Firmware Search vendor "Siemens" for product "Simatic Itc1500 Firmware" | >= 3.0.0.0 < 3.2.1.0 Search vendor "Siemens" for product "Simatic Itc1500 Firmware" and version " >= 3.0.0.0 < 3.2.1.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Itc1500 Search vendor "Siemens" for product "Simatic Itc1500" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Itc1500 Pro Firmware Search vendor "Siemens" for product "Simatic Itc1500 Pro Firmware" | >= 3.0.0.0 < 3.2.1.0 Search vendor "Siemens" for product "Simatic Itc1500 Pro Firmware" and version " >= 3.0.0.0 < 3.2.1.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Itc1500 Pro Search vendor "Siemens" for product "Simatic Itc1500 Pro" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Itc1900 Firmware Search vendor "Siemens" for product "Simatic Itc1900 Firmware" | >= 3.0.0.0 < 3.2.1.0 Search vendor "Siemens" for product "Simatic Itc1900 Firmware" and version " >= 3.0.0.0 < 3.2.1.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Itc1900 Search vendor "Siemens" for product "Simatic Itc1900" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Itc1900 Pro Firmware Search vendor "Siemens" for product "Simatic Itc1900 Pro Firmware" | >= 3.0.0.0 < 3.2.1.0 Search vendor "Siemens" for product "Simatic Itc1900 Pro Firmware" and version " >= 3.0.0.0 < 3.2.1.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Itc1900 Pro Search vendor "Siemens" for product "Simatic Itc1900 Pro" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Itc2200 Firmware Search vendor "Siemens" for product "Simatic Itc2200 Firmware" | >= 3.0.0.0 < 3.2.1.0 Search vendor "Siemens" for product "Simatic Itc2200 Firmware" and version " >= 3.0.0.0 < 3.2.1.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Itc2200 Search vendor "Siemens" for product "Simatic Itc2200" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Itc2200 Pro Firmware Search vendor "Siemens" for product "Simatic Itc2200 Pro Firmware" | >= 3.0.0.0 < 3.2.1.0 Search vendor "Siemens" for product "Simatic Itc2200 Pro Firmware" and version " >= 3.0.0.0 < 3.2.1.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Itc2200 Pro Search vendor "Siemens" for product "Simatic Itc2200 Pro" | - | - |
Safe
|
Libvncserver Project Search vendor "Libvncserver Project" | Libvncserver Search vendor "Libvncserver Project" for product "Libvncserver" | < 0.9.12 Search vendor "Libvncserver Project" for product "Libvncserver" and version " < 0.9.12" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 18.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "18.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 19.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "19.10" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 20.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "20.04" | lts |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Leap Search vendor "Opensuse" for product "Leap" | 15.1 Search vendor "Opensuse" for product "Leap" and version "15.1" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Leap Search vendor "Opensuse" for product "Leap" | 15.2 Search vendor "Opensuse" for product "Leap" and version "15.2" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 31 Search vendor "Fedoraproject" for product "Fedora" and version "31" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 32 Search vendor "Fedoraproject" for product "Fedora" and version "32" | - |
Affected
|