SB2021030129 - Fedora 33 update for x11vnc
Published: March 1, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2020-29074)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to x11vnc creates shared memory segments with 0777 mode in scan.c. A local user run a specially crafted program to gain access to sensitive information, trigger denial of service or interfere with the VNC session of another user on the host.
Remediation
Install update from vendor's website.