Security restrictions bypass in x11vnc - CVE-2020-29074

 

Security restrictions bypass in x11vnc - CVE-2020-29074

Published: November 26, 2020 / Updated: November 30, 2020


Vulnerability identifier: #VU48700
CSH Severity: Medium
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-29074
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to x11vnc creates shared memory segments with 0777 mode in scan.c. A local user run a specially crafted program to gain access to sensitive information, trigger denial of service or interfere with the VNC session of another user on the host.


Affected software

x11vnc
x11vnc (Debian package)
x11vnc (Alpine package)
x11vnc
Fedora

How to mitigate CVE-2020-29074

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

x11vnc (Debian package) - update to 0.9.13-6+deb10u1
x11vnc (Alpine package) - update to 0.9.16-r2
x11vnc - addressed in versions 0.9.13-12.el7, 0.9.16-3.el8, 0.9.16-3.fc32, 0.9.16-5.fc33, 0.9.16-6.fc34

External References

Related Security Bulletins