CVE-2020-29260: High severity libvncserver vulnerability
Published Sep 2, 2022
·Updated
libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().
Affected Software
2 affected components
Libvncserver Project Libvncserver=0.9.13
Debian Debian Linux=10.0
Remediation
Event History
Sep 2, 2022
CVE Published
via MITRE·10:14 PM
Data Sourced
via MITRE·10:14 PM
Description
Frequently Asked Questions
1
What is CVE-2020-29260?
CVE-2020-29260 is a vulnerability in libvncclient v0.9.13 that allows a memory leak through the function rfbClientCleanup().
2
What is the severity of CVE-2020-29260?
The severity of CVE-2020-29260 is high with a severity value of 7.5.
3
Which software versions are affected by CVE-2020-29260?
The affected software versions are libvncserver v0.9.13 and Debian Linux 10.0.
4
How can I fix CVE-2020-29260?
To fix CVE-2020-29260, update libvncserver to a version that includes the fix and apply any available patches.
5
Where can I find more information about CVE-2020-29260?
You can find more information about CVE-2020-29260 in the provided references: GitHub commit and Debian LTS announce.