An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:siemens:simatic_itc1500_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:simatic_itc1500_firmware",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "3.0.0.0"
},
{
"fixed": "3.2.1.0"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:simatic_itc1500_pro_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:simatic_itc1500_pro_firmware",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "3.0.0.0"
},
{
"fixed": "3.2.1.0"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:simatic_itc1900_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:simatic_itc1900_firmware",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "3.0.0.0"
},
{
"fixed": "3.2.1.0"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:simatic_itc1900_pro_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:simatic_itc1900_pro_firmware",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "3.0.0.0"
},
{
"fixed": "3.2.1.0"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:simatic_itc2200_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:simatic_itc2200_firmware",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "3.0.0.0"
},
{
"fixed": "3.2.1.0"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:simatic_itc2200_pro_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:simatic_itc2200_pro_firmware",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "3.0.0.0"
},
{
"fixed": "3.2.1.0"
}
]
},
{
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*"
],
"vendor_product": "canonical:ubuntu_linux",
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "14.04"
},
{
"last_affected": "14.04"
},
{
"introduced": "16.04"
},
{
"last_affected": "16.04"
},
{
"introduced": "16.04"
},
{
"last_affected": "16.04"
},
{
"introduced": "18.04"
},
{
"last_affected": "18.04"
},
{
"introduced": "18.10"
},
{
"last_affected": "18.10"
},
{
"introduced": "20.04"
},
{
"last_affected": "20.04"
}
]
},
{
"cpes": [
"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"vendor_product": "debian:debian_linux",
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "8.0"
},
{
"last_affected": "8.0"
},
{
"introduced": "9.0"
},
{
"last_affected": "9.0"
}
]
},
{
"cpes": [
"cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*"
],
"vendor_product": "opensuse:leap",
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "15.2"
},
{
"last_affected": "15.2"
}
]
}
]
}{
"cpe": "cpe:2.3:a:libvnc_project:libvncserver:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.12"
}
]
}
"2026-08-07T16:35:52Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-14398.json"
[
{
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"324641747666988017107537825977212487921",
"23468658264547528270405885375446689429",
"314499575584461443646606121383594492402",
"306615535104477164525540192538372084840",
"14242646121608592095535288825338715475",
"280000055704668278136952721231838649105",
"77168082287649511464652842806746410799",
"210755404642812292529507728767750616110",
"5412593350985301690771727771322932537",
"224006225380859415254987411028168719488",
"162495475645404325950860693104261241117",
"208548725558632311365373979711768969454",
"210755404642812292529507728767750616110",
"96712536681029417621070288510255798803"
],
"threshold": 0.9
},
"id": "CVE-2020-14398-475aebc7",
"source": "https://github.com/libvnc/libvncserver/commit/57433015f856cc12753378254ce4f1c78f5d9c7b",
"target": {
"file": "libvncclient/sockets.c"
}
},
{
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"233183713997520342950720743348847311279",
"293051295555592082169364195627676632234",
"236710258153632713615781603996356999439",
"81346176306328477675546311671981257623",
"229986401505472749873384896338511608079",
"121575258245161325243889731797089498050",
"207522311205809133671077703326120694040"
],
"threshold": 0.9
},
"id": "CVE-2020-14398-698de838",
"source": "https://github.com/libvnc/libvncserver/commit/57433015f856cc12753378254ce4f1c78f5d9c7b",
"target": {
"file": "rfb/rfbclient.h"
}
},
{
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"102909818689610700070936665680561590842",
"206285582406680325489952759430085590091",
"105327152294886155943177781097700765091",
"260389185708839503373468255712311087968"
],
"threshold": 0.9
},
"id": "CVE-2020-14398-c26dc7dd",
"source": "https://github.com/libvnc/libvncserver/commit/57433015f856cc12753378254ce4f1c78f5d9c7b",
"target": {
"file": "libvncclient/vncviewer.c"
}
},
{
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 3287.0,
"function_hash": "254707495691174405563156847212044692456"
},
"id": "CVE-2020-14398-c3c16db2",
"source": "https://github.com/libvnc/libvncserver/commit/57433015f856cc12753378254ce4f1c78f5d9c7b",
"target": {
"function": "rfbGetClient",
"file": "libvncclient/vncviewer.c"
}
},
{
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 3425.0,
"function_hash": "54417766686695289676091539773525012280"
},
"id": "CVE-2020-14398-d84cf98c",
"source": "https://github.com/libvnc/libvncserver/commit/57433015f856cc12753378254ce4f1c78f5d9c7b",
"target": {
"function": "ReadFromRFBServer",
"file": "libvncclient/sockets.c"
}
}
]