CVE-2019-15680
7.5
HIGH
CVSS 3.1
EPSS 0.73%
Description
TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System (DoS). This attack appear to be exploitable via network connectivity.
How to fix CVE-2019-15680
To remediate CVE-2019-15680, upgrade the affected package to a fixed version below.
- Debian/libvncserver—no fix listed
- Debian/tightvnc—upgrade to 1:1.3.9-9.1 or later
Is CVE-2019-15680 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0
- from 0, < 1:1.3.9-9.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |