Information disclosure in LibVNCServer - CVE-2020-14400

 

Information disclosure in LibVNCServer - CVE-2020-14400

Published: June 30, 2020


Vulnerability identifier: #VU29379
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14400
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. A remote authenticated user can gain unauthorized access to sensitive information on the system.


Affected software

LibVNCServer
libvncserver (Alpine package)
libvncclient1 (Ubuntu package)
libvncserver1 (Ubuntu package)
Opensuse
Ubuntu

How to mitigate CVE-2020-14400

Install updates from vendor's website.

LibVNCServer - update to 0.9.13
libvncserver (Alpine package) - update to 0.9.13-r0
libvncclient1 (Ubuntu package) - addressed in versions 0.9.10+dfsg-3ubuntu0.16.04.5, 0.9.11+dfsg-1ubuntu1.3, 0.9.12+dfsg-9ubuntu0.2
libvncserver1 (Ubuntu package) - addressed in versions 0.9.10+dfsg-3ubuntu0.16.04.5, 0.9.11+dfsg-1ubuntu1.3, 0.9.12+dfsg-9ubuntu0.2

External References

Related Security Bulletins