Lucene search

K
ubuntuUbuntuUSN-4547-1
HistorySep 28, 2020 - 12:00 a.m.

iTALC vulnerabilities

2020-09-2800:00:00
ubuntu.com
93
italc
information disclosure
libvncserver
remote code execution
ubuntu 18.04 esm

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.724

Percentile

98.1%

Releases

  • Ubuntu 18.04 ESM

Packages

  • italc - didact tool which allows teachers to view and control computer labs

Details

It was discovered that an information disclosure vulnerability existed in the
LibVNCServer vendored in iTALC when sending a ServerCutText message. An
attacker could possibly use this issue to expose sensitive information.
(CVE-2019-15681)

It was discovered that the LibVNCServer and LibVNCClient vendored in iTALC
incorrectly handled certain packet lengths. A remote attacker could possibly
use this issue to obtain sensitive information, cause a denial of service, or
execute arbitrary code.
(CVE-2018-15127 CVE-2018-20019, CVE-2018-20020, CVE-2018-20021, CVE-2018-20022,
CVE-2018-20023, CVE-2018-20024, CVE-2018-20748, CVE-2018-20749, CVE-2018-20750,
CVE-2018-7225, CVE-2019-15681)

OSVersionArchitecturePackageVersionFilename
Ubuntu18.04noarchitalc-client< 1:3.0.3+dfsg1-3ubuntu0.1UNKNOWN
Ubuntu18.04noarchitalc-client-dbgsym< 1:3.0.3+dfsg1-3ubuntu0.1UNKNOWN
Ubuntu18.04noarchitalc-management-console< 1:3.0.3+dfsg1-3ubuntu0.1UNKNOWN
Ubuntu18.04noarchitalc-management-console-dbgsym< 1:3.0.3+dfsg1-3ubuntu0.1UNKNOWN
Ubuntu18.04noarchitalc-master< 1:3.0.3+dfsg1-3ubuntu0.1UNKNOWN
Ubuntu18.04noarchitalc-master-dbgsym< 1:3.0.3+dfsg1-3ubuntu0.1UNKNOWN
Ubuntu18.04noarchlibitalccore< 1:3.0.3+dfsg1-3ubuntu0.1UNKNOWN
Ubuntu18.04noarchlibitalccore-dbgsym< 1:3.0.3+dfsg1-3ubuntu0.1UNKNOWN

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.724

Percentile

98.1%