SB2020113002 - Debian update for x11vnc



SB2020113002 - Debian update for x11vnc

Published: November 30, 2020

Security Bulletin ID SB2020113002
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Security restrictions bypass (CVE-ID: CVE-2020-29074)

The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to x11vnc creates shared memory segments with 0777 mode in scan.c. A local user run a specially crafted program to gain access to sensitive information, trigger denial of service or interfere with the VNC session of another user on the host.


Remediation

Install update from vendor's website.