Check Point Reference: | CPAI-2014-1903 |
Date Published: | 29 Oct 2014 |
Severity: | High |
Last Updated: | Wednesday 29 October, 2014 |
Source: | LibVNCServer 05a9bd41a |
Industry Reference: | CVE-2014-6054 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | LibVNCServer Development Team LibVNCServer 0.9.9 and prior |
Vulnerability Description | A denial of service vulnerability exists in LibVNCserver. The vulnerability is due to a division by zero when processing an rfbSetScale message. A remote authenticated attacker can exploit this vulnerability by sending a specially crafted RFB message to the server. |
SmartView Tracker will log the following entries:
Attack Name: Web Server Enforcement Violation.
Attack Information: LibVNCServer rfbProcessClientNormalMessage msg.ssc.scale Divide by Zero Denial of Service