An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c.
References
| Link | Resource |
|---|---|
| https://github.com/LibVNC/libvncserver/commit/57433015f856cc12753378254ce4f1c78f5d9c7b | Patch Third Party Advisory |
| https://github.com/LibVNC/libvncserver/compare/LibVNCServer-0.9.12...LibVNCServer-0.9.13 | Release Notes Third Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00033.html | Mailing List Third Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00055.html | Mailing List Third Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00066.html | |
| https://usn.ubuntu.com/4434-1/ | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-390195.pdf |
Information
Published : 2020-06-17 16:15
Updated : 2021-12-14 14:15
NVD link : CVE-2020-14398
Mitre link : CVE-2020-14398
JSON object : View
Products Affected
opensuse
- leap
libvncserver_project
- libvncserver
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
