LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade veyonUpgrade libvncserverUpgrade ssvncUpgrade tightvnc | Feb 4, 2019 | Dec 19, 2018 |
| Gentoo Linux | — | Upgrade net-libs/libvncserver.Upgrade net-misc/ssvnc. | Aug 13, 2019 | Dec 19, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 19, 2018 |
| Suse | — | Upgrade libvncclient0Upgrade LibVNCServerUpgrade LibVNCServer-develUpgrade libvncserver0 | Jan 11, 2019 | Dec 19, 2018 |
| Ubuntu | — | Upgrade libvncserver1Upgrade libvncserver0Upgrade italc-masterUpgrade ssvncUpgrade libvncclient1Upgrade libitalccoreUpgrade italc-client | Feb 6, 2019 | Dec 19, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub