CVE-2018-20021
19.12.2018, 16:29
LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM
Vendor | Product | Version |
---|---|---|
libvnc_project | libvncserver | 𝑥 < 0.9.12 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 18.10 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||
---|---|---|---|---|---|---|---|---|---|
libvncserver |
| ||||||||
ssvnc |
| ||||||||
tightvnc |
| ||||||||
veyon |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
italc |
| ||||||||||||||||||||||||||||
libvncserver |
| ||||||||||||||||||||||||||||
ssvnc |
| ||||||||||||||||||||||||||||
tightvnc |
| ||||||||||||||||||||||||||||
x11vnc |
|
Common Weakness Enumeration
References