LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.
[ { "signature_type": "Line", "deprecated": false, "source": "https://github.com/libvnc/libvncserver/commit/09e8fc02f59f16e2583b34fe1a270c238bd9ffec", "signature_version": "v1", "target": { "file": "libvncserver/rfbserver.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "208450598643815690107221870743096516411", "188468696327442976591528711100647299430", "339810309386704794107010451385675606359", "325020323779306967113667985277008054327", "252246010401280782980771499642649312175", "331557240631615908433514250914876982357", "326762681830792334858650571106630307146", "75410939976826082944537545891517174339" ] }, "id": "CVE-2018-20750-936cab71" }, { "signature_type": "Function", "deprecated": false, "source": "https://github.com/libvnc/libvncserver/commit/09e8fc02f59f16e2583b34fe1a270c238bd9ffec", "signature_version": "v1", "target": { "function": "rfbProcessFileTransferReadBuffer", "file": "libvncserver/rfbserver.c" }, "digest": { "function_hash": "7250474722688794593813454546579474339", "length": 639.0 }, "id": "CVE-2018-20750-a5a2e1bb" } ]