PT-2020-2982 · Libvnc+7 · Libvncserver+7
Published
2019-08-30
·
Updated
2022-03-09
·
CVE-2020-14405
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
LibVNCServer versions prior to 0.9.13
Description
The issue is related to the libvncclient/rfbproto.c component of the LibVNCServer library, where there is an unlimited memory allocation when accessing TextChat. This could allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. The problem arises because libvncclient/rfbproto.c does not limit the size of TextChat.
Recommendations
For versions prior to 0.9.13, update to version 0.9.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the TextChat feature until the update is applied.
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Libvncserver
Linuxmint
Red Hat
Rocky Linux
Ubuntu