cbcvebase.
CVE-2018-20021
published 2018-12-19

CVE-2018-20021: LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker…

PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.52%
87.8th percentile
LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM

Affected

19 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianlibvncserver< libvncserver 0.9.11+dfsg-1.2 (bookworm)libvncserver 0.9.11+dfsg-1.2 (bookworm)
debianssvnc< libvncserver 0.9.11+dfsg-1.2 (bookworm)libvncserver 0.9.11+dfsg-1.2 (bookworm)
debiantightvnc< libvncserver 0.9.11+dfsg-1.2 (bookworm)libvncserver 0.9.11+dfsg-1.2 (bookworm)
debianveyon< libvncserver 0.9.11+dfsg-1.2 (bookworm)libvncserver 0.9.11+dfsg-1.2 (bookworm)
libvnc_projectlibvncserver< 0.9.120.9.12
libvncserver_projectlibvncserver>= 0 < 0.9.11+dfsg-1.20.9.11+dfsg-1.2
libvncserver_projectlibvncserver>= 0 < 0.9.11+dfsg-1.20.9.11+dfsg-1.2
libvncserver_projectlibvncserver>= 0 < 0.9.11+dfsg-1.20.9.11+dfsg-1.2
libvncserver_projectlibvncserver>= 0 < 0.9.11+dfsg-1.20.9.11+dfsg-1.2
tightvnctightvnc>= 0 < 1:1.3.9-9.11:1.3.9-9.1
tightvnctightvnc>= 0 < 1:1.3.9-9.11:1.3.9-9.1
tightvnctightvnc>= 0 < 1:1.3.9-9.11:1.3.9-9.1
tightvnctightvnc>= 0 < 1:1.3.9-9.11:1.3.9-9.1

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.