LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ssvncUpgrade veyonUpgrade libvncserverUpgrade tightvnc | Feb 4, 2019 | Dec 19, 2018 |
| Gentoo Linux | — | Upgrade net-misc/ssvnc.Upgrade net-libs/libvncserver. | Aug 13, 2019 | Dec 19, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 19, 2018 |
| Suse | — | Upgrade libvncserver0Upgrade LibVNCServer-develUpgrade libvncclient0Upgrade LibVNCServer | Jan 11, 2019 | Dec 19, 2018 |
| Ubuntu | — | Upgrade libvncserver1Upgrade libvncserver0Upgrade libitalccoreUpgrade italc-masterUpgrade ssvncUpgrade libvncclient1Upgrade italc-client | Feb 6, 2019 | Dec 19, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub