CVE-2014-6054Divide By Zero in Libvncserver

Severity
4.3MEDIUMNVD
OSV7.5
EPSS
34.6%
top 2.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 6
Latest updateMay 13

Description

The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in the scaling factor in a (1) PalmVNCSetScaleFactor or (2) SetScale message.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

debiandebian/libvncserver< libvncserver 0.9.9+dfsg-6.1 (bookworm)
Debianlibvncserver_project/libvncserver< 0.9.9+dfsg-6.1+3
Ubuntulibvncserver_project/libvncserver< 0.9.9+dfsg-1ubuntu1.1

Also affects: Debian Linux 7.0, Ubuntu Linux 12.04, 14.04

Patches

🔴Vulnerability Details

4
GHSA
GHSA-246j-93ww-rg57: The rfbProcessClientNormalMessage function in libvncserver/rfbserver2022-05-13
OSV
italc vulnerabilities2020-10-20
OSV
CVE-2014-6054: The rfbProcessClientNormalMessage function in libvncserver/rfbserver2014-10-06
OSV
libvncserver vulnerabilities2014-09-29

📋Vendor Advisories

4
Ubuntu
iTALC vulnerabilities2020-10-20
Ubuntu
LibVNCServer vulnerabilities2014-09-29
Red Hat
libvncserver: server divide-by-zero flaw in scaling factor handling2014-09-23
Debian
CVE-2014-6054: libvncserver - The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNC...2014

💬Community

5
Bugzilla
CVE-2014-6051 CVE-2014-6053 CVE-2014-6052 CVE-2014-6055 CVE-2014-6054 krfb: various flaws [fedora-all]2014-09-24
Bugzilla
CVE-2014-6051 CVE-2014-6053 CVE-2014-6052 CVE-2014-6055 CVE-2014-6054 libvncserver: various flaws [fedora-all]2014-09-24
Bugzilla
CVE-2014-6051 CVE-2014-6053 CVE-2014-6052 CVE-2014-6055 CVE-2014-6054 libvncserver: various flaws [epel-5]2014-09-24
Bugzilla
CVE-2014-6051 CVE-2014-6053 CVE-2014-6052 CVE-2014-6055 libvncserver: various flaws [epel-7]2014-09-24
Bugzilla
CVE-2014-6054 libvncserver: server divide-by-zero flaw in scaling factor handling2014-09-19
CVE-2014-6054 — Divide By Zero in Debian Libvncserver | cvebase