LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Link | Tags |
---|---|
https://www.debian.org/security/2019/dsa-4383 | third party advisory vendor advisory |
https://lists.debian.org/debian-lts-announce/2018/12/msg00017.html | third party advisory mailing list |
https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/12/19/klcert-18-031-libvnc-infinite-loop/ | third party advisory |
https://usn.ubuntu.com/3877-1/ | third party advisory vendor advisory |
https://security.gentoo.org/glsa/201908-05 | vendor advisory |
https://lists.debian.org/debian-lts-announce/2019/10/msg00042.html | mailing list |
https://lists.debian.org/debian-lts-announce/2019/11/msg00033.html | mailing list |
https://lists.debian.org/debian-lts-announce/2019/12/msg00028.html | mailing list |
https://security.gentoo.org/glsa/202006-06 | vendor advisory |
https://usn.ubuntu.com/4547-1/ | vendor advisory |
https://usn.ubuntu.com/4547-2/ | vendor advisory |
https://usn.ubuntu.com/4587-1/ | vendor advisory |