CVE-2017-18922

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

Date published : 2020-06-30

https://lists.fedoraproject.org/archives/list/[email protected]/message/4F6FUH4EFK4NAP6GT4TQRTBKWIRCZLIY/

https://lists.fedoraproject.org/archives/list/[email protected]/message/NVP7TJVYJDXDFRHVQ3ENEN3H354QPXEZ/