← Back

CVE-2019-15681

nvd nist
Published: Oct 29, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appear to be exploitable via network connectivity. These vulnerabilities have been fixed in commit d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a.

Affected (14)

Show all products
Libvncserver
1 product
Ubuntu Linux
1 product
Debian Linux
6 products
Simatic Itc1500 Firmware
Simatic Itc1500 Pro Firmware
Simatic Itc1900 Firmware
Simatic Itc1900 Pro Firmware
Simatic Itc2200 Firmware
Simatic Itc2200 Pro Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.9.12
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.04
Version 16.04
Version 16.04
Version 18.04
Version 18.10
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 8.0
Version 9.0
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 3.0.0.0 to 3.2.1.0
Running on/withPlatform Versions
Siemens
Simatic Itc1500
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 3.0.0.0 to 3.2.1.0
Running on/withPlatform Versions
Siemens
Simatic Itc1500 Pro
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 3.0.0.0 to 3.2.1.0
Running on/withPlatform Versions
Siemens
Simatic Itc1900
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 3.0.0.0 to 3.2.1.0
Running on/withPlatform Versions
Siemens
Simatic Itc1900 Pro
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 3.0.0.0 to 3.2.1.0
Running on/withPlatform Versions
Siemens
Simatic Itc2200
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 3.0.0.0 to 3.2.1.0
Running on/withPlatform Versions
Siemens
Simatic Itc2200 Pro
All versions

References (24)

Source: vulnerability@kaspersky.com
Mailing ListThird Party Advisory
Source: vulnerability@kaspersky.com
Mailing ListThird Party Advisory
Source: vulnerability@kaspersky.com
Third Party Advisory
Source: vulnerability@kaspersky.com
PatchThird Party Advisory
Source: vulnerability@kaspersky.com
Mailing ListThird Party Advisory
Source: vulnerability@kaspersky.com
Mailing ListThird Party Advisory
Source: vulnerability@kaspersky.com
Mailing ListThird Party Advisory
Source: vulnerability@kaspersky.com
Mailing ListThird Party Advisory
Source: vulnerability@kaspersky.com
Third Party Advisory
Source: vulnerability@kaspersky.com
Third Party Advisory
Source: vulnerability@kaspersky.com
Third Party Advisory
Source: vulnerability@kaspersky.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.