CVE-2020-14397: Null Pointer Dereference
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13 - Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-14397.
What is the severity of CVE-2020-14397?
The severity of CVE-2020-14397 is high with a CVSS score of 7.5.
What is the affected software of CVE-2020-14397?
The affected software of CVE-2020-14397 includes libvncserver versions 0.9.11 to 0.9.13.
How can I fix CVE-2020-14397?
To fix CVE0-2020-14397, update libvncserver to version 0.9.14 or apply the appropriate remedy version provided by your Linux distribution.
Where can I find more information about CVE-2020-14397?
You can find more information about CVE-2020-14397 in the provided references: [link1](https://github.com/LibVNC/libvncserver/commit/38e98ee61d74f5f5ab4aa4c77146faad1962d6d0), [link2](https://github.com/LibVNC/libvncserver/compare/LibVNCServer-0.9.12...LibVNCServer-0.9.13), [link3](https://lists.debian.org/debian-lts-announce/2020/06/msg00035.html).