Lucene search

K
freebsdFreeBSDFB25333D-442F-11E4-98F3-5453ED2E2B49
HistorySep 23, 2014 - 12:00 a.m.

krfb -- Multiple security issues in bundled libvncserver

2014-09-2300:00:00
vuxml.freebsd.org
26

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.022

Percentile

89.5%

Martin Sandsmark reports:

krfb 4.14 [and earlier] embeds libvncserver which has had
several security issues.
Several remotely exploitable security issues have been
uncovered in libvncserver, some of which might allow a
remote authenticated user code execution or application
crashes.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchkrfb< 4.12.5_4UNKNOWN

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.022

Percentile

89.5%