CVE Vulnerabilities

CVE-2018-20021

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Dec 19, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
6.5 LOW
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
LibvncserverLibvnc_project*0.9.12 (excluding)
ItalcUbuntubionic*
ItalcUbuntuesm-apps/bionic*
ItalcUbuntuesm-apps/xenial*
ItalcUbuntutrusty*
ItalcUbuntuupstream*
ItalcUbuntuxenial*
LibvncserverUbuntubionic*
LibvncserverUbuntucosmic*
LibvncserverUbuntuesm-infra/bionic*
LibvncserverUbuntuesm-infra/xenial*
LibvncserverUbuntutrusty*
LibvncserverUbuntuupstream*
LibvncserverUbuntuxenial*
SsvncUbuntubionic*
SsvncUbuntuesm-apps/bionic*
SsvncUbuntuesm-apps/xenial*
SsvncUbuntutrusty*
SsvncUbuntuupstream*
SsvncUbuntuxenial*
TightvncUbuntubionic*
TightvncUbuntuesm-infra-legacy/trusty*
TightvncUbuntufocal*
TightvncUbuntugroovy*
TightvncUbuntuhirsute*
TightvncUbuntuimpish*
TightvncUbuntukinetic*
TightvncUbuntulunar*
TightvncUbuntumantic*
TightvncUbuntuoracular*
TightvncUbuntuplucky*
TightvncUbuntutrusty*
TightvncUbuntutrusty/esm*
TightvncUbuntuupstream*
TightvncUbuntuxenial*
X11vncUbuntucosmic*
X11vncUbuntutrusty*

References