CVE-2018-20021
HIGH7.5EPSS 2.6%發布日:2018/12/19修改日:2026/4/28
描述
LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM
受影響套件(4)
- Debian/libvncserverfrom 0, < 0.9.11+dfsg-1.2
- Debian/ssvncfrom 0, < 1.0.29-5
- Debian/tightvncfrom 0, < 1:1.3.9-9.1
- Debian/veyonfrom 0, < 4.1.4+repack1-1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |