CVE-2020-14400: High severity Libvncserver Project Libvncserver vulnerability
DISPUTED An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerability as there is no known path of exploitation or cross of a trust boundary.
Other sources
An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16t pointers in libvncserver/translate.c.
Upstream commit:
https://github.com/LibVNC/libvncserver/commit/53073c8d7e232151ea2ecd8a1243124121e10e2d
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13 - Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-14400.
What is the severity of CVE-2020-14400?
The severity of CVE-2020-14400 is high, with a severity value of 7.5.
What is the affected software?
The affected software includes LibVNCServer versions before 0.9.13.
Is there a known path of exploitation for CVE-2020-14400?
No, there is no known path of exploitation for CVE-2020-14400.
How can I fix CVE-2020-14400?
To fix CVE-2020-14400, update to version 0.9.13 or later of LibVNCServer.