Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6164
HistoryApr 20, 2018 - 7:52 a.m.

Denial Of Service (DoS) Through Integer Overflow

2018-04-2007:52:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

EPSS

0.003

Percentile

70.4%

libvncserver.so is vulnerable to denial of service (DoS) attacks. The vulnerability exists in the vcSetXCutTextProc function of VNConsole.c where there the improper sanitization of the client-specified message length could cause a denial of service (DoS) thorugh an integer overflow issue when processing a malicious VNC packet.