Ramin Farajpour Cami discovered that LibVNCServer incorrectly handled certain malformed unix socket names. A remote attacker could exploit this with a crafted socket name, leading to a denial of service, or possibly execute arbitrary code. (CVE-2019-20839)
It was discovered that LibVNCServer did not properly access byte-aligned data. A remote attacker could possibly use this issue to cause LibVNCServer to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 16.04 LTS. (CVE-2019-20840)
Christian Beier discovered that LibVNCServer incorrectly handled anonymous TLS connections. A remote attacker could possibly use this issue to cause LibVNCServer to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-14396)
It was discovered that LibVNCServer incorrectly handled region clipping. A remote attacker could possibly use this issue to cause LibVNCServer to crash, resulting in a denial of service. (CVE-2020-14397)
It was discovered that LibVNCServer did not properly reset incorrectly terminated TCP connections. A remote attacker could possibly use this issue to cause an infinite loop, resulting in a denial of service. (CVE-2020-14398)
It was discovered that LibVNCServer did not properly access byte-aligned data. A remote attacker could possibly use this issue to cause LibVNCServer to crash, resulting in a denial of service. (CVE-2020-14399, CVE-2020-14400)
It was discovered that LibVNCServer incorrectly handled screen scaling on the server side. A remote attacker could use this issue to cause LibVNCServer to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2020-14401)
It was discovered that LibVNCServer incorrectly handled encodings. A remote attacker could use this issue to cause LibVNCServer to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2020-14402, CVE-2020-14403, CVE-2020-14404)
It was discovered that LibVNCServer incorrectly handled TextChat messages. A remote attacker could possibly use this issue to cause LibVNCServer to crash, resulting in a denial of service. (CVE-2020-14405)
{ "availability": "No subscription required", "binaries": [ { "binary_version": "0.9.10+dfsg-3ubuntu0.16.04.5", "binary_name": "libvncclient1" }, { "binary_version": "0.9.10+dfsg-3ubuntu0.16.04.5", "binary_name": "libvncclient1-dbg" }, { "binary_version": "0.9.10+dfsg-3ubuntu0.16.04.5", "binary_name": "libvncclient1-dbgsym" }, { "binary_version": "0.9.10+dfsg-3ubuntu0.16.04.5", "binary_name": "libvncserver-config" }, { "binary_version": "0.9.10+dfsg-3ubuntu0.16.04.5", "binary_name": "libvncserver-config-dbgsym" }, { "binary_version": "0.9.10+dfsg-3ubuntu0.16.04.5", "binary_name": "libvncserver-dev" }, { "binary_version": "0.9.10+dfsg-3ubuntu0.16.04.5", "binary_name": "libvncserver-dev-dbgsym" }, { "binary_version": "0.9.10+dfsg-3ubuntu0.16.04.5", "binary_name": "libvncserver1" }, { "binary_version": "0.9.10+dfsg-3ubuntu0.16.04.5", "binary_name": "libvncserver1-dbg" }, { "binary_version": "0.9.10+dfsg-3ubuntu0.16.04.5", "binary_name": "libvncserver1-dbgsym" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "0.9.11+dfsg-1ubuntu1.3", "binary_name": "libvncclient1" }, { "binary_version": "0.9.11+dfsg-1ubuntu1.3", "binary_name": "libvncclient1-dbg" }, { "binary_version": "0.9.11+dfsg-1ubuntu1.3", "binary_name": "libvncserver-config" }, { "binary_version": "0.9.11+dfsg-1ubuntu1.3", "binary_name": "libvncserver-dev" }, { "binary_version": "0.9.11+dfsg-1ubuntu1.3", "binary_name": "libvncserver1" }, { "binary_version": "0.9.11+dfsg-1ubuntu1.3", "binary_name": "libvncserver1-dbg" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "0.9.12+dfsg-9ubuntu0.2", "binary_name": "libvncclient1" }, { "binary_version": "0.9.12+dfsg-9ubuntu0.2", "binary_name": "libvncclient1-dbgsym" }, { "binary_version": "0.9.12+dfsg-9ubuntu0.2", "binary_name": "libvncserver-dev" }, { "binary_version": "0.9.12+dfsg-9ubuntu0.2", "binary_name": "libvncserver1" }, { "binary_version": "0.9.12+dfsg-9ubuntu0.2", "binary_name": "libvncserver1-dbgsym" } ] }