Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-20021

Опубликовано: 19 дек. 2018
Источник: debian

Описание

LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libvncserverfixed0.9.11+dfsg-1.2package
italcremovedpackage
italcfixed1:3.0.3+dfsg1-1+deb9u1stretchpackage
ssvncfixed1.0.29-5package
ssvncfixed1.0.29-4+deb10u1busterpackage
ssvncfixed1.0.29-3+deb9u1stretchpackage
tightvncfixed1:1.3.9-9.1package
tightvncfixed1:1.3.9-9deb10u1busterpackage
tightvncfixed1:1.3.9-9+deb9u1stretchpackage
veyonfixed4.1.4+repack1-1package

Примечания

  • https://github.com/LibVNC/libvncserver/issues/251

  • https://github.com/LibVNC/libvncserver/commit/c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c

  • https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/12/19/klcert-18-031-libvnc-infinite-loop/

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 7 лет назад

LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM

CVSS3: 6.5
redhat
около 7 лет назад

LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM

CVSS3: 7.5
nvd
около 7 лет назад

LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM

CVSS3: 7.5
github
больше 3 лет назад

LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость библиотеки LibVNC, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании