PT-2020-10761 · Libvnc+6 · Libvncserver+6

Pavel Cheremushkin

·

Published

2019-11-17

·

Updated

2022-03-10

·

CVE-2019-20788

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibVNCServer versions 0.9.12 and earlier
Description The issue is related to an integer overflow and heap-based buffer overflow in the libvncclient/cursor.c file of LibVNCServer. This can be triggered via a large height or width value in the HandleCursorShape function.
Recommendations For LibVNCServer versions 0.9.12 and earlier, as a temporary workaround, consider restricting the input values for height and width to prevent large values from being processed by the HandleCursorShape function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2671
ALT-PU-2020-2694
CESA-2020_0913
CESA-2020_0920
CVE-2019-20788
DLA-2146-1
MGASA-2020-0207
OPENSUSE-SU-2020:0624-1
OPENSUSE-SU-2020_0624-1
OPENSUSE-SU-2024:10598-1
RHSA-2020:0913
RHSA-2020:0920
RHSA-2020:0921
RHSA-2020_0913
RHSA-2020_0920
SUSE-SU-2020:1164-1
SUSE-SU-2020:1164-2
SUSE-SU-2020:1165-1
SUSE-SU-2020:14355-1
USN-4407-1

Affected Products

Alt Linux
Centos
Libvncserver
Linuxmint
Red Hat
Suse
Ubuntu