CVE-2019-20840: High severity libvncserver vulnerability
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/wsdecode.c can lead to a crash because of unaligned accesses in hybiReadAndDecode.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-20840?
CVE-2019-20840 is a vulnerability discovered in LibVNCServer before version 0.9.13 that can lead to a crash due to unaligned accesses in hybiReadAndDecode.
How severe is CVE-2019-20840?
CVE-2019-20840 has a severity rating of 7.5, which is considered high.
Which software versions are affected by CVE-2019-20840?
The affected software versions include libvncserver 0.9.11+dfsg-1.3+deb10u4 to 0.9.11+dfsg-1.3+deb10u5, 0.9.13+dfsg-2+deb11u1, and 0.9.14+dfsg-1.
How can I fix CVE-2019-20840?
To fix CVE-2019-20840, update the libvncserver package to version 0.9.13 or higher.
Where can I find more information about CVE-2019-20840?
You can find more information about CVE-2019-20840 on the CVE Mitre website (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20840) and the LibVNCServer GitHub page (https://github.com/LibVNC/libvncserver/compare/LibVNCServer-0.9.12...LibVNCServer-0.9.13).