Security restrictions bypass in x11vnc - CVE-2020-29074
Published: November 26, 2020 / Updated: November 30, 2020
Vulnerability details
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to x11vnc creates shared memory segments with 0777 mode in scan.c. A local user run a specially crafted program to gain access to sensitive information, trigger denial of service or interfere with the VNC session of another user on the host.
Affected software
x11vnc (Debian package)
x11vnc (Alpine package)
x11vnc
Fedora
How to mitigate CVE-2020-29074
x11vnc (Alpine package) - update to 0.9.16-r2
x11vnc - addressed in versions 0.9.13-12.el7, 0.9.16-3.el8, 0.9.16-3.fc32, 0.9.16-5.fc33, 0.9.16-6.fc34