CVE-2019-20788: GHSL-2020-064: integer overflow in LibVNCClient HandleCursorShape resulting in remote heap overflow - CVE-2019-20788
Last updated 18 August 2025
Other sources
libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.
— Launchpad
There exists an integer overflow in HandleCursorShape RFB event handler in libvncclient, which is the client implementation for LibVNC included with libvncserver.
— GitHub Security Lab
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6 - Upgrade
Upgrade
libvncserver/libvncclient (LibVNCServer <= 0.9.12)to a version that resolves this vulnerability.Fixed in 0.9.12Patch CVE-2019-20788 - Upgrade
Upgrade
libvncserver/libvncclient (libvncclient/cursor.c HandleCursorShape)to a version that resolves this vulnerability.Patch GHSL-2020-064
Event History
Frequently Asked Questions
What is CVE-2019-20788?
CVE-2019-20788 is a vulnerability in LibVNCServer that allows an attacker to cause a heap-based buffer overflow by providing a large height or width value.
What is the severity of CVE-2019-20788?
CVE-2019-20788 has a severity rating of 9.8 (Critical).
How does CVE-2019-20788 affect LibVNCServer?
CVE-2019-20788 affects LibVNCServer versions up to 0.9.12.
How can I fix CVE-2019-20788?
To fix CVE-2019-20788, update LibVNCServer to version 0.9.13 or later.
Where can I find more information about CVE-2019-20788?
You can find more information about CVE-2019-20788 on the MITRE CVE website, Ubuntu security notices, and the NIST National Vulnerability Database.