CVE-2020-14401: Integer Overflow
Published Jun 17, 2020
·Updated
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixelvalue integer overflow.
Affected Software
30 affected componentsFixes available
Libvncserver Project Libvncserver<0.9.13
Debian Debian Linux=8.0
Debian Debian Linux=9.0
openSUSE Leap=15.1
openSUSE Leap=15.2
All of the following
Siemens Simatic Itc1500 Firmware>=3.0.0.0<3.2.1.0
Siemens Simatic Itc1500
All of the following
Siemens Simatic Itc1500 Pro Firmware>=3.0.0.0<3.2.1.0
Siemens Simatic Itc1500 Pro
All of the following
Siemens Simatic Itc1900 Firmware>=3.0.0.0<3.2.1.0
Siemens Simatic Itc1900
All of the following
Siemens Simatic Itc1900 Pro Firmware>=3.0.0.0<3.2.1.0
Siemens Simatic Itc1900 Pro
All of the following
Siemens Simatic Itc2200 Firmware>=3.0.0.0<3.2.1.0
Siemens Simatic Itc2200
All of the following
Siemens Simatic Itc2200 Pro Firmware>=3.0.0.0<3.2.1.0
Siemens Simatic Itc2200 Pro
Siemens Simatic Itc1500 Firmware>=3.0.0.0<3.2.1.0
Siemens Simatic Itc1500
Siemens Simatic Itc1500 Pro Firmware>=3.0.0.0<3.2.1.0
Siemens Simatic Itc1500 Pro
Siemens Simatic Itc1900 Firmware>=3.0.0.0<3.2.1.0
Siemens Simatic Itc1900
Siemens Simatic Itc1900 Pro Firmware>=3.0.0.0<3.2.1.0
Siemens Simatic Itc1900 Pro
Siemens Simatic Itc2200 Firmware>=3.0.0.0<3.2.1.0
Siemens Simatic Itc2200
Siemens Simatic Itc2200 Pro Firmware>=3.0.0.0<3.2.1.0
Siemens Simatic Itc2200 Pro
debian/libvncserver
0.9.13+dfsg-2+deb11u10.9.14+dfsg-1+deb12u10.9.15+dfsg-1+deb13u10.9.15+dfsg-6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6 - Upgrade
Upgrade
libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13
Event History
Jun 17, 2020
CVE Published
via MITRE·03:12 PM
Data Sourced
via MITRE·03:12 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:40 PM
Description
Jul 21, 2025
Data Sourced
via Ubuntu·04:05 AM
RemedyDescriptionSeverityAffected Software
Jul 5, 2026
Data Sourced
via Debian·02:52 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-14401.
2
What is the severity of CVE-2020-14401?
The severity of CVE-2020-14401 is medium with a CVSS score of 6.5.
3
How does CVE-2020-14401 impact LibVNCServer?
CVE-2020-14401 allows attackers to cause a pixel_value integer overflow in LibVNCServer before version 0.9.13.
4
What is the remedy for CVE-2020-14401 in Debian?
The remedy for CVE-2020-14401 in Debian is to update to version 0.9.13+dfsg-2+deb11u1 or later.
5
What is the remedy for CVE-2020-14401 in Ubuntu?
The remedy for CVE-2020-14401 in Ubuntu is to update to version 0.9.12+dfsg-9ubuntu0.2 or later.