CVE-2019-20839: Buffer Overflow
Last updated 24 July 2024
Other sources
libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-20839?
CVE-2019-20839 is a vulnerability in LibVNCServer that allows a buffer overflow via a long socket filename.
How severe is CVE-2019-20839?
CVE-2019-20839 has a severity score of 7.5 (high).
Which software versions are affected by CVE-2019-20839?
The affected software versions of CVE-2019-20839 are: libvncserver 0.9.11+dfsg-1.3+deb10u4, 0.9.11+dfsg-1.3+deb10u5, 0.9.13+dfsg-2+deb11u1, and 0.9.14+dfsg-1 (from Debian) and libvncserver 0.9.11+dfsg-1ubuntu1.3 (from Ubuntu).
How can I fix CVE-2019-20839?
To fix CVE-2019-20839, update to libvncserver version 0.9.13+dfsg-2+deb11u1 (from Debian) or libvncserver version 0.9.11+dfsg-1ubuntu1.3 (from Ubuntu).
Where can I find more information about CVE-2019-20839?
You can find more information about CVE-2019-20839 at the following references: [GitHub](https://github.com/LibVNC/libvncserver/commit/3fd03977c9b35800d73a865f167338cb4d05b0c1), [GitHub](https://github.com/LibVNC/libvncserver/compare/LibVNCServer-0.9.12...LibVNCServer-0.9.13), [Debian LTS](https://lists.debian.org/debian-lts-announce/2020/06/msg00035.html).