Bugzilla – Bug 1120121
VUL-0: CVE-2018-20024: LibVNCServer: NULL pointer dereference in VNC client code allows for denial of service
Last modified: 2019-04-29 10:16:35 UTC
rh#1661132 / CVE-2018-20024 LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS. External Reference: https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/12/19/klcert-18-034-libvnc-null-pointer-dereference/ Upstream Patch: https://github.com/LibVNC/libvncserver/commit/4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 References: https://bugzilla.redhat.com/show_bug.cgi?id=1661132 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-20024 http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-20024.html
openSUSE x11vnc is also affected.
Submitted also to devel project as 0.9.12 is not out yet (sr#662702). I believe all fixed.
SUSE-SU-2019:0060-1: An update that fixes 9 vulnerabilities is now available. Category: security (important) Bug References: 1120114,1120115,1120116,1120117,1120118,1120119,1120120,1120121,1120122 CVE References: CVE-2018-15126,CVE-2018-15127,CVE-2018-20019,CVE-2018-20020,CVE-2018-20021,CVE-2018-20022,CVE-2018-20023,CVE-2018-20024,CVE-2018-6307 Sources used: SUSE OpenStack Cloud 7 (src): LibVNCServer-0.9.9-17.8.1 SUSE Linux Enterprise Software Development Kit 12-SP4 (src): LibVNCServer-0.9.9-17.8.1 SUSE Linux Enterprise Software Development Kit 12-SP3 (src): LibVNCServer-0.9.9-17.8.1 SUSE Linux Enterprise Server for SAP 12-SP2 (src): LibVNCServer-0.9.9-17.8.1 SUSE Linux Enterprise Server 12-SP4 (src): LibVNCServer-0.9.9-17.8.1 SUSE Linux Enterprise Server 12-SP3 (src): LibVNCServer-0.9.9-17.8.1 SUSE Linux Enterprise Server 12-SP2-LTSS (src): LibVNCServer-0.9.9-17.8.1 SUSE Linux Enterprise Server 12-SP2-BCL (src): LibVNCServer-0.9.9-17.8.1 SUSE Linux Enterprise Server 12-SP1-LTSS (src): LibVNCServer-0.9.9-17.8.1 SUSE Linux Enterprise Server 12-LTSS (src): LibVNCServer-0.9.9-17.8.1 SUSE Enterprise Storage 4 (src): LibVNCServer-0.9.9-17.8.1
SUSE-SU-2019:13927-1: An update that fixes 8 vulnerabilities is now available. Category: security (important) Bug References: 1120114,1120115,1120116,1120117,1120118,1120120,1120121,1120122 CVE References: CVE-2018-15126,CVE-2018-15127,CVE-2018-20019,CVE-2018-20020,CVE-2018-20021,CVE-2018-20022,CVE-2018-20024,CVE-2018-6307 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): LibVNCServer-0.9.1-160.6.1 SUSE Linux Enterprise Server 11-SP4 (src): LibVNCServer-0.9.1-160.6.1 SUSE Linux Enterprise Server 11-SP3-LTSS (src): LibVNCServer-0.9.1-160.6.1 SUSE Linux Enterprise Point of Sale 11-SP3 (src): LibVNCServer-0.9.1-160.6.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): LibVNCServer-0.9.1-160.6.1 SUSE Linux Enterprise Debuginfo 11-SP3 (src): LibVNCServer-0.9.1-160.6.1
This is an autogenerated message for OBS integration: This bug (1120121) was mentioned in https://build.opensuse.org/request/show/664669 Factory / LibVNCServer
SUSE-SU-2019:0080-1: An update that fixes 9 vulnerabilities is now available. Category: security (important) Bug References: 1120114,1120115,1120116,1120117,1120118,1120119,1120120,1120121,1120122 CVE References: CVE-2018-15126,CVE-2018-15127,CVE-2018-20019,CVE-2018-20020,CVE-2018-20021,CVE-2018-20022,CVE-2018-20023,CVE-2018-20024,CVE-2018-6307 Sources used: SUSE Linux Enterprise Workstation Extension 15 (src): LibVNCServer-0.9.10-4.3.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15 (src): LibVNCServer-0.9.10-4.3.1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src): LibVNCServer-0.9.10-4.3.1
openSUSE-SU-2019:0045-1: An update that fixes 9 vulnerabilities is now available. Category: security (important) Bug References: 1120114,1120115,1120116,1120117,1120118,1120119,1120120,1120121,1120122 CVE References: CVE-2018-15126,CVE-2018-15127,CVE-2018-20019,CVE-2018-20020,CVE-2018-20021,CVE-2018-20022,CVE-2018-20023,CVE-2018-20024,CVE-2018-6307 Sources used: openSUSE Leap 42.3 (src): LibVNCServer-0.9.9-16.6.1
openSUSE-SU-2019:0053-1: An update that fixes 9 vulnerabilities is now available. Category: security (important) Bug References: 1120114,1120115,1120116,1120117,1120118,1120119,1120120,1120121,1120122 CVE References: CVE-2018-15126,CVE-2018-15127,CVE-2018-20019,CVE-2018-20020,CVE-2018-20021,CVE-2018-20022,CVE-2018-20023,CVE-2018-20024,CVE-2018-6307 Sources used: openSUSE Leap 15.0 (src): LibVNCServer-0.9.10-lp150.3.3.1
rekleased
SUSE-SU-2019:0060-2: An update that fixes 9 vulnerabilities is now available. Category: security (important) Bug References: 1120114,1120115,1120116,1120117,1120118,1120119,1120120,1120121,1120122 CVE References: CVE-2018-15126,CVE-2018-15127,CVE-2018-20019,CVE-2018-20020,CVE-2018-20021,CVE-2018-20022,CVE-2018-20023,CVE-2018-20024,CVE-2018-6307 Sources used: SUSE Linux Enterprise Server for SAP 12-SP1 (src): LibVNCServer-0.9.9-17.8.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.