CVE-2014-6052: Input Validation
Published Dec 15, 2014
·Updated
Last updated 24 July 2024
Other sources
The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibV ...
— Debian
Affected Software
7 affected componentsFixes available
LibVNCServer LibVNCServer<=0.9.9
Oracle Solaris=11.3
Debian Debian Linux=7.0
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
debian/libvncserver
0.9.13+dfsg-2+deb11u10.9.14+dfsg-10.9.15+dfsg-1
debian/veyon
4.5.3+repack1-14.7.5+repack1-14.9.5+repack1-2
Remediation
Event History
Dec 15, 2014
CVE Published
via MITRE·05:27 PM
Data Sourced
via MITRE·05:27 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:05 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:04 AM
RemedyDescriptionSeverityAffected Software
Feb 27, 2025
Data Sourced
via Debian·01:58 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2014-6052?
CVE-2014-6052 is a vulnerability in LibVNCServer that allows remote VNC servers to cause a denial of service or possibly execute arbitrary code.
2
How does CVE-2014-6052 affect LibVNCServer?
CVE-2014-6052 affects LibVNCServer versions 0.9.9 and earlier by not checking certain malloc return values.
3
What is the severity of CVE-2014-6052?
CVE-2014-6052 has a severity score of 7.5, which is considered high.
4
How can CVE-2014-6052 be fixed?
To fix CVE-2014-6052, update LibVNCServer to version 0.9.10 or later.
5
Where can I find more information about CVE-2014-6052?
More information about CVE-2014-6052 can be found at the following references: [1] [2] [3].