Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25708

Опубликовано: 13 мая 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a floating point exception, resulting in a denial of service.

A divide by zero flaw was found in libvncserver. This flaw allows a malicious client to send a specially crafted message that, when processed by the VNC server, leads to a floating-point exception, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvncserverOut of support scope
Red Hat Enterprise Linux 6vinoOut of support scope
Red Hat Enterprise Linux 7libvncserverOut of support scope
Red Hat Enterprise Linux 7vinoOut of support scope
Red Hat Enterprise Linux 8vinoWill not fix
Red Hat Enterprise Linux 8libvncserverFixedRHSA-2021:181118.05.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-369
https://bugzilla.redhat.com/show_bug.cgi?id=1896739libvncserver: libvncserver/rfbserver.c has a divide by zero which could result in DoS

EPSS

Процентиль: 40%
0.00177
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a floating point exception, resulting in a denial of service.

CVSS3: 7.5
nvd
больше 4 лет назад

A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a floating point exception, resulting in a denial of service.

CVSS3: 7.5
debian
больше 4 лет назад

A divide by zero issue was found to occur in libvncserver-0.9.12. A ma ...

suse-cvrf
больше 4 лет назад

Security update for LibVNCServer

suse-cvrf
больше 4 лет назад

Security update for LibVNCServer

EPSS

Процентиль: 40%
0.00177
Низкий

7.5 High

CVSS3