Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32854

Опубликовано: 24 мар. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within httpProcessInput() in httpd.c that allow remote attackers to cause a denial of service by sending specially crafted HTTP requests. Attackers can exploit missing validation of strchr() return values in the CONNECT and GET proxy handling paths to trigger null pointer dereferences and crash the server when httpd and proxy features are enabled.

A flaw was found in LibVNCServer. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by sending specially crafted HTTP requests. The flaw exists in the HTTP proxy handlers, where missing validation of certain return values can lead to a null pointer dereference, causing the server to crash. This impacts the availability of the server when HTTPD and proxy features are enabled.

Отчет

The availability impact of this flaw is limited on Red Hat products. While an attacker may be able to induce a crash in the LibVNCServer the host Red Hat system's availability is not at risk. Additionally, unless configured otherwise Red Hat Linux will automatically reboot LibVNCServer in the event of a crash.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvncserverFix deferred
Red Hat Enterprise Linux 7libvncserverNot affected
Red Hat Enterprise Linux 8libvncserverWill not fix
Red Hat Enterprise Linux 9gnome-remote-desktopAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2450845LibVNCServer: LibVNCServer: Denial of Service via specially crafted HTTP requests

EPSS

Процентиль: 92%
0.05322
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within httpProcessInput() in httpd.c that allow remote attackers to cause a denial of service by sending specially crafted HTTP requests. Attackers can exploit missing validation of strchr() return values in the CONNECT and GET proxy handling paths to trigger null pointer dereferences and crash the server when httpd and proxy features are enabled.

CVSS3: 7.5
nvd
5 месяцев назад

LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within httpProcessInput() in httpd.c that allow remote attackers to cause a denial of service by sending specially crafted HTTP requests. Attackers can exploit missing validation of strchr() return values in the CONNECT and GET proxy handling paths to trigger null pointer dereferences and crash the server when httpd and proxy features are enabled.

CVSS3: 7.5
debian
5 месяцев назад

LibVNCServer versions 0.9.15 and prior (fixed incommit dc78dee) contai ...

suse-cvrf
4 месяца назад

Security update for LibVNCServer

suse-cvrf
4 месяца назад

Security update for LibVNCServer

EPSS

Процентиль: 92%
0.05322
Низкий

5.3 Medium

CVSS3