TCP Connection Flaw in LibVNCServer Affects Multiple Platforms
CVE-2020-14398

7.5HIGH

Key Information:

Vendor
CVE Published:
17 June 2020

Summary

LibVNCServer prior to version 0.9.13 has a flaw that arises from an improperly closed TCP connection, leading to an infinite loop in the handling of socket connections. This vulnerability can potentially disrupt the functionality of remote access services and compromise system performance. It is crucial for users operating affected versions to update to the latest release to mitigate risks associated with this defect.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.