ZeroHour

CVE-2017-18922

CVSS 3.1
9.8 critical
EPSS
2%p82
Published
()
Modified
Description

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

Vendors
libvncserver projectcanonicalopensusefedoraprojectsiemens
Products
libvncserver, ubuntu linux, leap, fedora, simatic itc1500 firmware, simatic itc1500 pro firmware, simatic itc1900 firmware, simatic itc1900 pro firmware, simatic itc2200 firmware, simatic itc2200 pro firmware
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.