CVE-2020-14404: Medium severity Libvnc Project Libvncserver vulnerability
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6 - Upgrade
Upgrade
libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13
Event History
Frequently Asked Questions
What is CVE-2020-14404?
CVE-2020-14404 is a vulnerability discovered in LibVNCServer that allows out-of-bounds access via encodings.
How severe is CVE-2020-14404?
CVE-2020-14404 has a severity rating of 5.4, which is considered medium.
Which software is affected by CVE-2020-14404?
LibVNCServer versions before 0.9.13 are affected by CVE-2020-14404.
Where can I find more information about CVE-2020-14404?
You can find more information about CVE-2020-14404 on the MITRE CVE database and the Ubuntu security notices website.
How can I fix CVE-2020-14404?
To fix CVE-2020-14404, you should update LibVNCServer to version 0.9.13 or later.