CVE-2014-6055: Buffer Overflow

Published Sep 19, 2014
·
Updated

Last updated 24 July 2024

Other sources

Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) directory name or the (3) FileTime attribute in a rfbFileTransferOffer message.

Launchpad

Two stack-based buffer overflow flaws were reported in LibVNCServer's file transfer handling. A VNC client could use these flaws to cause the VNC server to crash or, potentially, execute arbitrary code.

Upstream commits:

https://github.com/newsoft/libvncserver/commit/06ccdf016154fde8eccb5355613ba04c59127b2e

https://github.com/newsoft/libvncserver/commit/f528072216dec01cee7ca35d94e171a3b909e677

Red Hat

Affected Software

7 affected componentsFixes available
Fedoraproject Fedora=20
Fedoraproject Fedora=21
Debian Debian Linux=7.0
redhat Enterprise Linux Server Aus=6.5
redhat Enterprise Linux Server Eus=6.5.z
LibVNCServer LibVNCServer<=0.9.9
debian/libvncserver
0.9.13+dfsg-2+deb11u10.9.14+dfsg-10.9.15+dfsg-1

Event History

Sep 19, 2014
Data Sourced
via Red Hat·07:42 AM
DescriptionSeverityAffected Software
Sep 30, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:05 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:04 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the vulnerability ID for this vulnerability?

The vulnerability ID for this vulnerability is CVE-2014-6055.

2

What is the severity level of CVE-2014-6055?

The severity level of CVE-2014-6055 is medium, with a severity value of 6.5.

3

Which software versions are affected by CVE-2014-6055?

CVE-2014-6055 affects LibVNCServer 0.9.9 and earlier, Fedora 20 and 21, Debian Linux 7.0, Red Hat Enterprise Linux Server Aus 6.5, Red Hat Enterprise Linux Server Eus 6.5.z, and Ubuntu packages krfb and libvncserver.

4

How can a remote authenticated user exploit CVE-2014-6055?

A remote authenticated user can exploit CVE-2014-6055 by causing a denial of service (crash) and possibly executing arbitrary code via a long file or directory name or the FileTime attribute in a rfbserver.c file.

5

Where can I find more information about CVE-2014-6055?

You can find more information about CVE-2014-6055 at the following references: [link1](http://lists.fedoraproject.org/pipermail/package-announce/2014-October/139654.html), [link2](http://lists.fedoraproject.org/pipermail/package-announce/2014-September/139445.html), [link3](http://lists.opensuse.org/opensuse-updates/2015-12/msg00022.html).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203