Back
CVE-2018-15126
CRITICAL
LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution
Published: Dec 19, 2018
Modified: Jun 17, 2026
CWE-416
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (7)
| Vendor | Product | Version |
|---|---|---|
| libvnc_project | libvncserver | * < 0.9.12 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
GitHub Security Advisory GHSA-792h-432f-5q3w
LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free...
References (10)
- https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/12/19/klcert-18-027-libvnc-heap-use-after-free/ Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/01/msg00029.html Mailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00042.html
- https://usn.ubuntu.com/3877-1/ Third Party Advisory
- https://www.debian.org/security/2019/dsa-4383 Third Party Advisory
- https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/12/19/klcert-18-027-libvnc-heap-use-after-free/ Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/01/msg00029.html Mailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00042.html
- https://usn.ubuntu.com/3877-1/ Third Party Advisory
- https://www.debian.org/security/2019/dsa-4383 Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
11.81%
Top 4% most likely to be exploited
Threat Score
42.7 / 100
Data Sources
NVD
EPSS
GitHub