CVE-2018-20024

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-20024
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20024.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-20024
Related
Published
2018-12-19T16:29:00Z
Modified
2025-01-14T07:27:41.929769Z
Downstream
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS.

References

Affected packages

Debian:11 / libvncserver

Package

Name
libvncserver
Purl
pkg:deb/debian/libvncserver?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.11+dfsg-1.2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / libvncserver

Package

Name
libvncserver
Purl
pkg:deb/debian/libvncserver?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.11+dfsg-1.2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / libvncserver

Package

Name
libvncserver
Purl
pkg:deb/debian/libvncserver?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.11+dfsg-1.2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / ssvnc

Package

Name
ssvnc
Purl
pkg:deb/debian/ssvnc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.29-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / ssvnc

Package

Name
ssvnc
Purl
pkg:deb/debian/ssvnc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.29-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / ssvnc

Package

Name
ssvnc
Purl
pkg:deb/debian/ssvnc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.29-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / veyon

Package

Name
veyon
Purl
pkg:deb/debian/veyon?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.4+repack1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / veyon

Package

Name
veyon
Purl
pkg:deb/debian/veyon?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.4+repack1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / veyon

Package

Name
veyon
Purl
pkg:deb/debian/veyon?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.4+repack1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/libvnc/libvncserver

Affected ranges

Type
GIT
Repo
https://github.com/libvnc/libvncserver
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

LibVNCServer-0.*

LibVNCServer-0.9.10
LibVNCServer-0.9.11
LibVNCServer-0.9.8
LibVNCServer-0.9.9

Other

X11VNC_0_9_10
X11VNC_0_9_11
X11VNC_0_9_12
X11VNC_0_9_7
X11VNC_0_9_8
X11VNC_0_9_9
X11VNC_REL_0_9_4
X11VNC_REL_0_9_5
X11VNC_REL_0_9_6