CVE-2010-5304
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
05/02/2020
Last modified:
21/11/2024
Description
A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A remote attacker could use this flaw to crash the VNC server by sending a specially crafted ClientCutText message from a VNC client.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:libvncserver_project:libvncserver:*:*:*:*:*:*:*:* | 0.9.9 (excluding) | |
| cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.fedoraproject.org/pipermail/package-announce/2014-October/139654.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-October/139814.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-October/140219.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-September/139445.html
- http://seclists.org/oss-sec/2014/q3/639
- http://www.openwall.com/lists/oss-security/2014/09/23/6
- http://lists.fedoraproject.org/pipermail/package-announce/2014-October/139654.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-October/139814.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-October/140219.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-September/139445.html
- http://seclists.org/oss-sec/2014/q3/639
- http://www.openwall.com/lists/oss-security/2014/09/23/6



