PT-2020-2982 · Libvnc+7 · Libvncserver+7

Published

2019-08-30

·

Updated

2022-03-09

·

CVE-2020-14405

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions LibVNCServer versions prior to 0.9.13
Description The issue is related to the libvncclient/rfbproto.c component of the LibVNCServer library, where there is an unlimited memory allocation when accessing TextChat. This could allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. The problem arises because libvncclient/rfbproto.c does not limit the size of TextChat.
Recommendations For versions prior to 0.9.13, update to version 0.9.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the TextChat feature until the update is applied.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:1811
ALT-PU-2019-2585
ALT-PU-2019-2662
ALT-PU-2020-2671
ALT-PU-2020-2694
BDU:2020-03149
CESA-2021_1811
CVE-2020-14405
DLA-2264-1
DLA-2347-1
MGASA-2020-0280
RHSA-2021:1811
RHSA-2021_1811
RLSA-2021:1811
USN-4434-1

Affected Products

Alt Linux
Almalinux
Centos
Libvncserver
Linuxmint
Red Hat
Rocky Linux
Ubuntu