HIGH · 7.5

CVE-2019-15681

LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclo...

Vulnerability Description

LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appear to be exploitable via network connectivity. These vulnerabilities have been fixed in commit d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Libvnc ProjectLibvncserver< 0.9.12
CanonicalUbuntu Linux14.04
DebianDebian Linux8.0
SiemensSimatic Itc1500 Firmware>= 3.0.0.0, < 3.2.1.0
SiemensSimatic Itc1500-
SiemensSimatic Itc1500 Pro Firmware>= 3.0.0.0, < 3.2.1.0
SiemensSimatic Itc1500 Pro-
SiemensSimatic Itc1900 Firmware>= 3.0.0.0, < 3.2.1.0
SiemensSimatic Itc1900-
SiemensSimatic Itc1900 Pro Firmware>= 3.0.0.0, < 3.2.1.0
SiemensSimatic Itc1900 Pro-
SiemensSimatic Itc2200 Firmware>= 3.0.0.0, < 3.2.1.0
SiemensSimatic Itc2200-
SiemensSimatic Itc2200 Pro Firmware>= 3.0.0.0, < 3.2.1.0
SiemensSimatic Itc2200 Pro-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-15681?

CVE-2019-15681 is a vulnerability with a CVSS score of 7.5 (HIGH). LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclo...

How severe is CVE-2019-15681?

CVE-2019-15681 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-15681?

Check the references section above for vendor advisories and patch information. Affected products include: Libvnc Project Libvncserver, Canonical Ubuntu Linux, Debian Debian Linux, Siemens Simatic Itc1500 Firmware, Siemens Simatic Itc1500.