Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-5304

Опубликовано: 23 сент. 2014
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A remote attacker could use this flaw to crash the VNC server by sending a specially crafted ClientCutText message from a VNC client.

A flaw was found in realvnc. LibVNCServer, in versions prior to 0.9.9, contain a NULL pointer dereference when handling certain ClientCutText messages which could be used by a remote attacker to crash the VNC server. The highest threat from this vulnerability is to system availability.

Отчет

This flaw is in RealVNC shipped with Red Hat Enterprise Linux 5. A similar flaw was also found in LibVNCServer and was assigned CVE-2014-6053

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5vncOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1804723realvnc: Null pointer dereference flaw in ClientCutText message handling

EPSS

Процентиль: 87%
0.03383
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 6 лет назад

A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A remote attacker could use this flaw to crash the VNC server by sending a specially crafted ClientCutText message from a VNC client.

CVSS3: 7.5
github
почти 4 года назад

A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A remote attacker could use this flaw to crash the VNC server by sending a specially crafted ClientCutText message from a VNC client.

EPSS

Процентиль: 87%
0.03383
Низкий

7.5 High

CVSS3