Infinite Loop Vulnerability in LibVNC Client Code from LibVNC Vendor
CVE-2018-20021
7.5HIGH
Summary
A vulnerability exists in the LibVNC client code that allows an attacker to exploit an infinite loop condition. By triggering this vulnerability, an attacker can monopolize system resources, rendering the device unresponsive due to excessive CPU and RAM consumption. This makes it crucial for users of affected versions to apply the necessary security updates to prevent potential exploitation.
Affected Version(s)
LibVNC commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved