CVE-2018-20021: High severity Libvnc Project Libvncserver vulnerability
Last updated 11 July 2025
Other sources
LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6 - Upgrade
Upgrade
debian/ssvncto a version that resolves this vulnerability.Fixed in 1.0.29-5Fixed in 1.0.29-6Fixed in 1.0.29-6.1Fixed in 1.0.29-7 - Upgrade
Upgrade
debian/tightvncto a version that resolves this vulnerability.Fixed in 1:1.3.10-3Fixed in 1:1.3.10-7Fixed in 1:1.3.10-9Fixed in 1:1.3.10-11 - Upgrade
Upgrade
debian/veyonto a version that resolves this vulnerability.Fixed in 4.5.3+repack1-1Fixed in 4.7.5+repack1-1Fixed in 4.9.5+repack1-2Fixed in 4.9.7+repack1-1.1 - Upgrade
Upgrade
LibVNCto a version that resolves this vulnerability.Patch c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-20021.
What is the severity of CVE-2018-20021?
The severity of CVE-2018-20021 is high, with a severity value of 7.5.
What is the description of CVE-2018-20021?
CVE-2018-20021 is a vulnerability in LibVNC that allows an attacker to consume excessive resources like CPU and RAM due to an infinite loop.
Which software versions are affected by CVE-2018-20021?
CVE-2018-20021 affects multiple versions of LibVNC, including 0.9.12 and earlier, 1:3.0.3+dfsg1-3ubuntu0.1 and earlier, and 1:2.0.2+dfsg1-2+ and earlier.
Is there a fix available for CVE-2018-20021?
Yes, a fix for CVE-2018-20021 is available. Users should update to commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c or a later version of LibVNC.