Executive brief
LibVNCServer is a library used by developers to implement VNC (Virtual Network Computing) server functionality, allowing remote desktop access. A vulnerability in its built-in web server component allows a remote attacker to crash the server by sending a specially formatted web request. This results in a denial of service, preventing legitimate users from accessing the remote desktop until the service is manually restarted.
Technical details
Two NULL pointer dereference vulnerabilities exist in the httpProcessInput() function within httpd.c. The root cause is a failure to validate the return value of strchr() when processing HTTP CONNECT and GET proxy requests. Specifically, a CONNECT request missing a colon or a GET request missing a forward slash causes strchr() to return NULL, which is subsequently dereferenced by atoi() or strncmp(). This vulnerability is exploitable by an unauthenticated remote attacker if the non-default '-httpd' and '-enablehttpproxy' options are enabled. A fix is available in commit dc78dee.
Affected products
- LibVNC LibVNCServer <= 0.9.15
Timeline
- 2026-03-24: disclosed
- 2026-03-24: advisory
- 2026-03-24: patched: Fixed in commit dc78dee