PT-2019-5437 · Libvnc+5 · Libvncserver+5

Publicado

2019-12-18

·

Atualizado

2022-03-10

·

CVE-2020-14398

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions LibVNCServer versions prior to 0.9.13
Description The issue is related to an infinite loop in the libvncclient/sockets.c component of the LibVNCServer library. This occurs due to an improperly closed TCP connection, which can be exploited by a remote attacker to cause a denial of service. The exploitation may result from the incorrect closure of a TCP connection, leading to the infinite loop.
Recommendations For versions prior to 0.9.13, update to version 0.9.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the libvncclient/sockets.c component to minimize the risk of exploitation.

Correção

Infinite Loop

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-2671
ALT-PU-2020-2694
BDU:2020-03158
CVE-2020-14398
MGASA-2020-0280
OPENSUSE-SU-2020:0988-1
OPENSUSE-SU-2020:1025-1
OPENSUSE-SU-2020:1056-1
OPENSUSE-SU-2020_0988-1
OPENSUSE-SU-2020_1025-1
OPENSUSE-SU-2020_1056-1
OPENSUSE-SU-2024:10598-1
SUSE-SU-2020:14424-1
SUSE-SU-2020:1922-1
SUSE-SU-2020:2167-1
USN-4434-1

Produtos afetados

Alt Linux
Astra Linux
Libvncserver
Linuxmint
Suse
Ubuntu