Vulnerability Name:

CVE-2019-15680 (CCN-170453)

Assigned:2018-12-10
Published:2018-12-10
Updated:2020-12-09
Summary:TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System (DoS). This attack appear to be exploitable via network connectivity.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-476
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2019-15680

Source: CONFIRM
Type: UNKNOWN
https://cert-portal.siemens.com/productcert/pdf/ssa-478893.pdf

Source: XF
Type: UNKNOWN
tightvnc-cve201915680-dos(170453)

Source: MLIST
Type: UNKNOWN
[debian-lts-announce] 20191221 [SECURITY] [DLA 2045-1] tightvnc security update

Source: MISC
Type: UNKNOWN
https://us-cert.cisa.gov/ics/advisories/icsa-20-343-08

Source: UBUNTU
Type: UNKNOWN
USN-4407-1

Source: CCN
Type: oss-sec Mailing List, Mon, 10 Dec 2018 12:48:43 +0000
libvnc and tightvnc vulnerabilities

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20181210 libvnc and tightvnc vulnerabilities

Source: CCN
Type: TightVNC Web site
TightVNC

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2019-15680

Vulnerable Configuration:Configuration 1:
  • cpe:/a:tightvnc:tightvnc:1.3.10:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:tightvnc:tightvnc:1.3.10:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201915680
    V
    CVE-2019-15680
    2022-05-20
    oval:org.opensuse.security:def:30291
    P
    Security update for libsndfile (Important)
    2022-01-05
    oval:org.opensuse.security:def:34598
    P
    Security update for java-1_7_0-openjdk (Important)
    2021-11-24
    oval:org.opensuse.security:def:29449
    P
    Security update for webkit2gtk3 (Important)
    2021-11-23
    oval:org.opensuse.security:def:31708
    P
    Security update for webkit2gtk3 (Important)
    2021-11-23
    oval:org.opensuse.security:def:30123
    P
    Security update for file (Important)
    2021-09-02
    oval:org.opensuse.security:def:31255
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-08-25
    oval:org.opensuse.security:def:33702
    P
    Security update for cpio (Important)
    2021-08-23
    oval:org.opensuse.security:def:30112
    P
    Security update for MozillaFirefox (Important)
    2021-08-17
    oval:org.opensuse.security:def:30111
    P
    Security update for libcares2 (Important)
    2021-08-16
    oval:org.opensuse.security:def:31664
    P
    Security update for cpio (Important)
    2021-08-14
    oval:org.opensuse.security:def:31642
    P
    Security update for webkit2gtk3 (Important)
    2021-06-17
    oval:org.opensuse.security:def:31198
    P
    Security update for caribou (Important)
    2021-06-10
    oval:org.opensuse.security:def:36437
    P
    libblkid-devel-2.19.1-6.72.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36395
    P
    empathy-2.28.2-0.13.49 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:34451
    P
    Security update for polkit (Important)
    2021-06-03
    oval:org.opensuse.security:def:33658
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:30197
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:33634
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:31603
    P
    Security update for fwupdate (Important)
    2021-04-08
    oval:org.opensuse.security:def:33092
    P
    Security update for wpa_supplicant (Important)
    2021-03-09
    oval:org.opensuse.security:def:35288
    P
    Security update for the Linux Kernel (Important)
    2021-03-09
    oval:org.opensuse.security:def:28937
    P
    Security update for screen (Important)
    2021-02-17
    oval:org.opensuse.security:def:31342
    P
    Security update for screen (Important)
    2021-02-17
    oval:org.opensuse.security:def:34508
    P
    Security update for openvswitch (Important)
    2021-02-02
    oval:org.opensuse.security:def:32957
    P
    Security update for postgresql, postgresql12, postgresql13 (Important)
    2021-01-26
    oval:org.opensuse.security:def:34340
    P
    Security update for MozillaFirefox (Critical)
    2020-12-21
    oval:org.opensuse.security:def:28868
    P
    Security update for python (Important)
    2020-12-11
    oval:org.opensuse.security:def:35231
    P
    Security update for the Linux Kernel (Important)
    2020-12-09
    oval:org.opensuse.security:def:31562
    P
    Security update for xen (Important)
    2020-12-07
    oval:org.opensuse.security:def:35652
    P
    xorg-x11-7.4-9.24.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35611
    P
    mailman-2.1.12-0.1.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:28857
    P
    Security update for gdm (Important)
    2020-12-03
    oval:org.opensuse.security:def:35757
    P
    libnewt0_52-0.52.10-1.35.7 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35713
    P
    gstreamer-0_10-plugins-base-0.10.35-5.15.8 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35685
    P
    dhcp-4.2.3.P2-0.7.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35646
    P
    unzip-5.52-142.23.43 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35597
    P
    libpoppler-glib4-0.12.3-1.2.44 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35538
    P
    e2fsprogs-1.41.9-2.1.51 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:28856
    P
    Security update for python3 (Important)
    2020-12-02
    oval:org.opensuse.security:def:30900
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:28228
    P
    Security update for libssh2_org (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30889
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:28144
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:33595
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:30328
    P
    Security update for tightvnc (Important)
    2020-12-01
    oval:org.opensuse.security:def:30888
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:28087
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33546
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:28003
    P
    security update for xen (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33489
    P
    Security update for libsndfile
    2020-12-01
    oval:org.opensuse.security:def:29653
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27875
    P
    Security update for rubygem-activesupport
    2020-12-01
    oval:org.opensuse.security:def:33332
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:29609
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:27811
    P
    Security update for LibreOffice
    2020-12-01
    oval:org.opensuse.security:def:33244
    P
    python-pam on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29591
    P
    Security update for apport (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27800
    P
    Security update for libmspack (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33187
    P
    libtiff3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29552
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27799
    P
    Security update for libmspack
    2020-12-01
    oval:org.opensuse.security:def:29503
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34973
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34929
    P
    Security update for facter (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32878
    P
    guestfs-data on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29296
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:34903
    P
    Security update for dhcpcd (Important)
    2020-12-01
    oval:org.opensuse.security:def:32867
    P
    gd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29211
    P
    Security update for openvpn (Important)
    2020-12-01
    oval:org.opensuse.security:def:34864
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:31600
    P
    Security update for tightvnc (Important)
    2020-12-01
    oval:org.opensuse.security:def:32866
    P
    g3utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29154
    P
    Security update for libssh2_org (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34815
    P
    Security update for apport (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29068
    P
    Security update for clamav (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34757
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:30924
    P
    Security update for gdb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30880
    P
    Security update for file
    2020-12-01
    oval:org.opensuse.security:def:30860
    P
    Security update for e2fsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30821
    P
    Security update for CUPS
    2020-12-01
    oval:org.opensuse.security:def:34353
    P
    Security update for sudo, sudo-debuginfo, sudo-debugsource
    2020-12-01
    oval:org.opensuse.security:def:30772
    P
    Security update for augeas (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34217
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30717
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:34133
    P
    Security update for ntp (Important)
    2020-12-01
    oval:org.opensuse.security:def:30562
    P
    Security update for pcp
    2020-12-01
    oval:org.opensuse.security:def:34122
    P
    Security update for ncurses (Important)
    2020-12-01
    oval:org.opensuse.security:def:30475
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:32385
    P
    Security update for tightvnc (Important)
    2020-12-01
    oval:org.opensuse.security:def:34121
    P
    Security update for ncurses (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30418
    P
    Security update for xorg-x11-libXfixes (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32346
    P
    Security update for sqlite3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30329
    P
    Security update for tomcat6 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35378
    P
    Security update for ntp (Important)
    2020-12-01
    oval:org.opensuse.security:def:29255
    P
    Security update for tightvnc (Important)
    2020-12-01
    oval:org.opensuse.security:def:35130
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31554
    P
    Security update for sqlite3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29219
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:34994
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:31498
    P
    Security update for python-numpy (Important)
    2020-12-01
    oval:org.opensuse.security:def:28581
    P
    Security update for LibreOffice
    2020-12-01
    oval:org.opensuse.security:def:34910
    P
    Security update for dosfstools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28537
    P
    Security update for compat-openssl097g
    2020-12-01
    oval:org.opensuse.security:def:34899
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28521
    P
    Security update for openvpn-openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:34380
    P
    Security update for tightvnc (Important)
    2020-12-01
    oval:org.opensuse.security:def:34898
    P
    Security update for dbus-1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:28482
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31106
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:28433
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30974
    P
    Security update for gtk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28380
    P
    Security update for rubygem-actionpack-3_2 (Moderate)
    2020-12-01
    oval:com.ubuntu.disco:def:2019156800000000
    V
    CVE-2019-15680 on Ubuntu 19.04 (disco) - low.
    2019-10-29
    oval:com.ubuntu.bionic:def:2019156800000000
    V
    CVE-2019-15680 on Ubuntu 18.04 LTS (bionic) - low.
    2019-10-29
    oval:com.ubuntu.xenial:def:2019156800000000
    V
    CVE-2019-15680 on Ubuntu 16.04 LTS (xenial) - low.
    2019-10-29
    BACK
    tightvnc tightvnc 1.3.10
    tightvnc tightvnc 1.3.10