PT-2026-27461 · Unknown+2 · Libvncserver+2
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
LibVNCServer versions prior to the commit dc78dee
LibVNCServer version 0.9.15
Description
The software contains null pointer dereference issues in the HTTP proxy handlers within the
httpProcessInput() function in httpd.c. These issues allow remote attackers to cause a denial of service by sending specially crafted HTTP requests. Specifically, missing validation of the strchr() return values in the CONNECT and GET proxy handling paths can trigger null pointer dereferences, leading to a server crash when httpd and proxy features are enabled.Recommendations
Update LibVNCServer to a version after the commit dc78dee.
Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libvncserver
Linuxmint
Ubuntu