CVE-2020-14402: Medium severity Libvnc Project Libvncserver vulnerability
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6 - Upgrade
Upgrade
libvncserver/corre.cto a version that resolves this vulnerability.Fixed in 0.9.13
Event History
Frequently Asked Questions
What is CVE-2020-14402?
CVE-2020-14402 is a vulnerability that was discovered in LibVNCServer before version 0.9.13 which allows for out-of-bounds access via encodings.
How severe is CVE-2020-14402?
CVE-2020-14402 has a severity score of 5.4 out of 10, indicating a medium severity.
Which software versions are affected by CVE-2020-14402?
The affected software versions for CVE-2020-14402 are libvncserver 0.9.12+dfsg-9ubuntu0.2, libvncserver 0.9.11+dfsg-1ubuntu1.3, and libvncserver 0.9.10+dfsg-3ubuntu0.16.04.5.
How can I fix CVE-2020-14402?
To fix CVE-2020-14402, you should update LibVNCServer to version 0.9.13 or later.
Where can I find more information about CVE-2020-14402?
You can find more information about CVE-2020-14402 on the CVE website (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14402) and the LibVNCServer GitHub page (https://github.com/LibVNC/libvncserver/compare/LibVNCServer-0.9.12...LibVNCServer-0.9.13).