LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appear to be exploitable via network connectivity. These vulnerabilities have been fixed in commit d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
History
21 Nov 2024, 04:29
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00027.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00073.html - Mailing List, Third Party Advisory | |
References | () https://cert-portal.siemens.com/productcert/pdf/ssa-390195.pdf - Third Party Advisory | |
References | () https://github.com/LibVNC/libvncserver/commit/d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a - Patch, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2019/10/msg00039.html - Mailing List, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2019/10/msg00042.html - Mailing List, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2019/11/msg00032.html - Mailing List, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2019/12/msg00028.html - Mailing List, Third Party Advisory | |
References | () https://usn.ubuntu.com/4407-1/ - Third Party Advisory | |
References | () https://usn.ubuntu.com/4547-1/ - Third Party Advisory | |
References | () https://usn.ubuntu.com/4573-1/ - Third Party Advisory | |
References | () https://usn.ubuntu.com/4587-1/ - Third Party Advisory |
Information
Published : 2019-10-29 19:15
Updated : 2024-11-21 04:29
NVD link : CVE-2019-15681
Mitre link : CVE-2019-15681
CVE.ORG link : CVE-2019-15681
JSON object : View
Products Affected
siemens
- simatic_itc1900
- simatic_itc2200_firmware
- simatic_itc1500_pro
- simatic_itc1900_pro_firmware
- simatic_itc1500
- simatic_itc2200_pro
- simatic_itc1900_firmware
- simatic_itc1500_firmware
- simatic_itc1500_pro_firmware
- simatic_itc1900_pro
- simatic_itc2200
- simatic_itc2200_pro_firmware
libvnc_project
- libvncserver
canonical
- ubuntu_linux
debian
- debian_linux
CWE
CWE-665
Improper Initialization