CVE-2018-20021

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM

References

https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/12/19/klcert-18-031-libvnc-infinite-loop/

https://lists.debian.org/debian-lts-announce/2018/12/msg00017.html

https://lists.debian.org/debian-lts-announce/2019/10/msg00042.html

https://lists.debian.org/debian-lts-announce/2019/11/msg00033.html

https://lists.debian.org/debian-lts-announce/2019/12/msg00028.html

https://security.gentoo.org/glsa/201908-05

https://security.gentoo.org/glsa/202006-06

https://usn.ubuntu.com/3877-1/

https://usn.ubuntu.com/4547-1/

https://usn.ubuntu.com/4547-2/

https://usn.ubuntu.com/4587-1/

https://www.debian.org/security/2019/dsa-4383

Details

Source: MITRE

Published: 2018-12-19

Updated: 2020-10-23

Type: CWE-835

Risk Information

CVSS v2

Base Score: 7.8

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Impact Score: 6.9

Exploitability Score: 10

Severity: HIGH

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 3.9

Severity: HIGH

Tenable Plugins

View all (16 total)

IDNameProductFamilySeverity
141545Ubuntu 16.04 LTS : iTALC vulnerabilities (USN-4587-1)NessusUbuntu Local Security Checks
critical
140929Ubuntu 16.04 LTS : SSVNC vulnerabilities (USN-4547-2)NessusUbuntu Local Security Checks
critical
140920Ubuntu 18.04 LTS : iTALC vulnerabilities (USN-4547-1)NessusUbuntu Local Security Checks
critical
137443GLSA-202006-06 : ssvnc: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
132345Debian DLA-2045-1 : tightvnc security updateNessusDebian Local Security Checks
critical
131434Debian DLA-2016-1 : ssvnc security updateNessusDebian Local Security Checks
critical
130408Debian DLA-1979-1 : italc security updateNessusDebian Local Security Checks
critical
127563GLSA-201908-05 : LibVNCServer: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
121561Debian DSA-4383-1 : libvncserver - security updateNessusDebian Local Security Checks
critical
121541Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS / 18.10 : LibVNCServer vulnerabilities (USN-3877-1)NessusUbuntu Local Security Checks
critical
121282openSUSE Security Update : LibVNCServer (openSUSE-2019-53)NessusSuSE Local Security Checks
critical
121160SUSE SLES11 Security Update : LibVNCServer (SUSE-SU-2019:13927-1)NessusSuSE Local Security Checks
critical
121158SUSE SLED15 / SLES15 Security Update : LibVNCServer (SUSE-SU-2019:0080-1)NessusSuSE Local Security Checks
critical
121154openSUSE Security Update : LibVNCServer (openSUSE-2019-45)NessusSuSE Local Security Checks
critical
121094SUSE SLES12 Security Update : LibVNCServer (SUSE-SU-2019:0060-1)NessusSuSE Local Security Checks
critical
119877Debian DLA-1617-1 : libvncserver security updateNessusDebian Local Security Checks
critical