PT-2022-7505 · Unknown+4 · Libvncclient+4

Ramin Farajpour Cami

·

Published

2022-09-02

·

Updated

2025-01-28

·

CVE-2020-29260

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libvncclient version 0.9.13
Description The issue is related to a memory leak in the rfbClientCleanup() function of the libvncclient component. This memory leak can be exploited by a remote attacker to cause a denial of service.
Recommendations For libvncclient version 0.9.13, consider disabling the rfbClientCleanup() function as a temporary workaround until a patch is available.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2923
ALT-PU-2022-2962
ALT-PU-2022-3020
BDU:2024-06666
CVE-2020-29260
DLA-3125-1
MGASA-2022-0363
OESA-2022-2090
OPENSUSE-SU-2022_3540-1
OPENSUSE-SU-2022_3990-1
OPENSUSE-SU-2024:12313-1
ROSA-SA-2025-2628
SUSE-SU-2022:3540-1
SUSE-SU-2022:3990-1
SUSE-SU-2022:4330-1
SUSE-SU-2022_3540-1
SUSE-SU-2022_3990-1
SUSE-SU-2022_4330-1

Affected Products

Alt Linux
Astra Linux
Red Os
Suse
Libvncclient