CVE-2020-14405: Medium severity Libvnc Project Libvncserver vulnerability
An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13 - Upgrade
Upgrade
debian/libvncserverto a version that resolves this vulnerability.Fixed in 0.9.13+dfsg-2+deb11u1Fixed in 0.9.14+dfsg-1+deb12u1Fixed in 0.9.15+dfsg-1+deb13u1Fixed in 0.9.15+dfsg-6
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-14405.
What is the severity of CVE-2020-14405?
The severity of CVE-2020-14405 is medium with a severity value of 6.5.
Which software versions are affected by CVE-2020-14405?
The affected software versions for CVE-2020-14405 are libvncserver 0.9.11+dfsg-1.3+deb10u4, 0.9.11+dfsg-1.3+deb10u5, 0.9.13+dfsg-2+deb11u1, and 0.9.14+dfsg-1.
How can I fix CVE-2020-14405?
To fix CVE-2020-14405, update libvncserver to version 0.9.13 or later.
Where can I find more information about CVE-2020-14405?
More information about CVE-2020-14405 can be found on the following references: [link1](https://github.com/LibVNC/libvncserver/commit/8937203441ee241c4ace85da687b7d6633a12365), [link2](https://github.com/LibVNC/libvncserver/compare/LibVNCServer-0.9.12...LibVNCServer-0.9.13), [link3](https://lists.debian.org/debian-lts-announce/2020/06/msg00035.html).