CVE-2020-14399 PUBLISHED

An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c. NOTE: there is reportedly "no trust boundary crossed.

EPSS 2.46% · 85.1th percentile

Risk Scores

EPSS Score
2.46%
85.1th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlibvncserver0.9.11+dfsg-1ubuntu1.2, 0.9.11+dfsg-1ubuntu1.1, 0.9.11+dfsg-1ubuntu1
Ubuntu:20.04:LTSlibvncserver0.9.12+dfsg-8, 0.9.12+dfsg-9, 0.9.12+dfsg-9ubuntu0.1
Ubuntu:16.04:LTSlibvncserver0.9.10+dfsg-3ubuntu0.16.04.3, 0.9.10+dfsg-3ubuntu0.16.04.4, 0.9.10+dfsg-3ubuntu0.16.04.2

Timeline

References

Open in Interactive Console →