It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

Project Subscriptions

Vendors Products
Canonical Subscribe
Ubuntu Linux Subscribe
Fedoraproject Subscribe
Libvncserver Project Subscribe
Libvncserver Subscribe
Opensuse Subscribe
Enterprise Linux Subscribe
Rhel E4s Subscribe
Rhel Eus Subscribe
Siemens Subscribe
Simatic Itc1500 Subscribe
Simatic Itc1500 Firmware Subscribe
Simatic Itc1500 Pro Subscribe
Simatic Itc1500 Pro Firmware Subscribe
Simatic Itc1900 Subscribe
Simatic Itc1900 Firmware Subscribe
Simatic Itc1900 Pro Subscribe
Simatic Itc1900 Pro Firmware Subscribe
Simatic Itc2200 Subscribe
Simatic Itc2200 Firmware Subscribe
Simatic Itc2200 Pro Subscribe
Simatic Itc2200 Pro Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2017-10012 It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.
Ubuntu USN Ubuntu USN USN-4407-1 LibVNCServer vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T21:45:24.570Z

Reserved: 2020-06-30T00:00:00.000Z

Link: CVE-2017-18922

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-06-30T11:15:10.380

Modified: 2024-11-21T03:21:16.067

Link: CVE-2017-18922

cve-icon Redhat

Severity : Important

Publid Date: 2017-02-15T00:00:00Z

Links: CVE-2017-18922 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses