Information disclosure in LibVNCServer - CVE-2020-14399

 

Information disclosure in LibVNCServer - CVE-2020-14399

Published: June 30, 2020


Vulnerability identifier: #VU29380
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14399
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c. A remote authenticated user can gain unauthorized access to sensitive information on the system.


Affected software

LibVNCServer
libvncserver (Alpine package)
libvncclient1 (Ubuntu package)
libvncserver1 (Ubuntu package)
Opensuse
Ubuntu

How to mitigate CVE-2020-14399

Install updates from vendor's website.

LibVNCServer - update to 0.9.13
libvncserver (Alpine package) - update to 0.9.13-r0
libvncclient1 (Ubuntu package) - addressed in versions 0.9.10+dfsg-3ubuntu0.16.04.5, 0.9.11+dfsg-1ubuntu1.3, 0.9.12+dfsg-9ubuntu0.2
libvncserver1 (Ubuntu package) - addressed in versions 0.9.10+dfsg-3ubuntu0.16.04.5, 0.9.11+dfsg-1ubuntu1.3, 0.9.12+dfsg-9ubuntu0.2

External References

Related Security Bulletins