CVE-2019-15690: Buffer Overflow
Last updated 18 August 2025
Other sources
LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6 - Upgrade
Upgrade
LibVNCServerto a version that resolves this vulnerability.Patch 54220248886b5001fbbb9fa73c4e1a2cb9413fed
Event History
Frequently Asked Questions
What is CVE-2019-15690?
CVE-2019-15690 is a heap buffer overflow vulnerability in libvncclient/cursor.c related to large cursor sizes when connected to a malicious server.
What software versions are affected by CVE-2019-15690?
The affected software versions are libvncserver 0.9.11+dfsg-1ubuntu1.2, 0.9.11+dfsg-1.3ubuntu0.1, 0.9.12+dfsg-9ubuntu0.1, 0.9.10+dfsg-3ubuntu0.16.04.4, and various versions of libvncserver in Debian.
How severe is CVE-2019-15690?
CVE-2019-15690 has a severity score of 7.8 (High) according to the CVSS v3.1 scoring system.
How can I fix CVE-2019-15690?
To fix CVE-2019-15690, you should update libvncserver to the recommended versions provided by the respective vendors, such as 0.9.11+dfsg-1ubuntu1.2 for Ubuntu and the patched versions for Debian when available.
Where can I find more information about CVE-2019-15690?
You can find more information about CVE-2019-15690 on the MITRE CVE website (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15690) and the Ubuntu security notices (https://ubuntu.com/security/notices/USN-4407-1).