libvncserver: websocket decoding buffer overflow
Published Jun 30, 2020
9.8
CRITICALCVSS 3.1
EPSS 2.26%
Description
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.
Affected products
No data.
Configuration 1
- < 0.9.12
Configuration 2
- 16.04
- 18.04
- 19.10
- 20.04
Configuration 4
- 31
- 32
Configuration 5
- ≥ 3.0.0.0 · < 3.2.1.0
Running on/with
- n/a
Configuration 6
- ≥ 3.0.0.0 · < 3.2.1.0
Running on/with
- n/a
Configuration 7
- ≥ 3.0.0.0 · < 3.2.1.0
Running on/with
- n/a
Configuration 8
- ≥ 3.0.0.0 · < 3.2.1.0
Running on/with
- n/a
Configuration 9
- ≥ 3.0.0.0 · < 3.2.1.0
Running on/with
- n/a
Configuration 10
- ≥ 3.0.0.0 · < 3.2.1.0
Running on/with
- n/a
No data.
Red Hat Enterprise Linux 7
libvncserver-0:0.9.9-14.el7_8.1
Fixed · RHSA-2020:3281
Red Hat Enterprise Linux 8
libvncserver-0:0.9.11-15.el8_2.1
Fixed · RHSA-2020:3385
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
libvncserver-0:0.9.11-9.el8_0.3
Fixed · RHSA-2020:3588
Red Hat Enterprise Linux 8.1 Extended Update Support
libvncserver-0:0.9.11-9.el8_1.3
Fixed · RHSA-2020:3456
Red Hat Enterprise Linux 6
libvncserver
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | libvncserver-0:0.9.9-14.el7_8.1 | Fixed | RHSA-2020:3281 |
| Red Hat Enterprise Linux 8 | libvncserver-0:0.9.11-15.el8_2.1 | Fixed | RHSA-2020:3385 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | libvncserver-0:0.9.11-9.el8_0.3 | Fixed | RHSA-2020:3588 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | libvncserver-0:0.9.11-9.el8_1.3 | Fixed | RHSA-2020:3456 |
| Red Hat Enterprise Linux 6 | libvncserver | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.26% (0.02259) | 82.35th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.26% (0.02259) | 80.63th | v5 (v2026.06.15) |
| Apr 22, 2026 | 6.87% (0.06869) | 91.40th | v4 (v2025.03.14) |
| Dec 28, 2025 | 4.78% (0.04777) | 89.11th | v4 (v2025.03.14) |
| Dec 27, 2025 | 2.98% (0.02980) | 86.16th | v4 (v2025.03.14) |
| Oct 28, 2025 | 4.78% (0.04777) | 88.95th | v4 (v2025.03.14) |
| Oct 27, 2025 | 2.98% (0.02980) | 86.04th | v4 (v2025.03.14) |
| Oct 1, 2025 | 4.78% (0.04777) | 89.05th | v4 (v2025.03.14) |
| Jul 30, 2025 | 2.98% (0.02980) | 86.00th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.42% (0.04420) | 88.28th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.40% (0.00401) | 74.45th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.40% (0.00401) | 72.92th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.40% (0.00401) | 70.33th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.36% (0.00364) | 67.99th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.69% (0.02686) | 62.66th | v2 (v2022.01.01) |
| Feb 3, 2022 | 3.06% (0.03055) | 65.09th | v5 (v2026.06.15) |
| Apr 14, 2021 | 2.84% (0.02841) | 0.00th | v1 |
References (16)
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00020.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00028.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00033.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00055.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00066.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2020/06/30/3 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-18922 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1852356 x_refsource_MISCIssue TrackingThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-390195.pdf x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/LibVNC/libvncserver/commit/aac95a9dcf4bbba87b76c72706c3221a842ca433 x_refsource_MISCPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4F6FUH4EFK4NAP6GT4TQRTBKWIRCZLIY/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NVP7TJVYJDXDFRHVQ3ENEN3H354QPXEZ/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2017-18922
- https://usn.ubuntu.com/4407-1/ vendor-advisoryx_refsource_UBUNTUPatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-18922
- https://www.openwall.com/lists/oss-security/2020/06/30/2 x_refsource_MISCMailing ListThird Party Advisory
Change history (0)
No recorded changes yet.