Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-20788

Опубликовано: 17 нояб. 2019
Источник: redhat
CVSS3: 0

Описание

libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.

A flaw was found in libvncserver in versions through 0.9.12. A large height or width value may cause an integer overflow or a heap-based buffer overflow. The highest threat from this vulnerability is to system availability.

Отчет

This flaw was found to be a duplicate of CVE-2019-15690. Please see https://access.redhat.com/security/cve/CVE-2019-15690 for information about affected products and security errata.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvncserverNot affected
Red Hat Enterprise Linux 7libvncserverFixedRHSA-2020:091323.03.2020
Red Hat Enterprise Linux 8libvncserverFixedRHSA-2020:092023.03.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionslibvncserverFixedRHSA-2020:092123.03.2020

Показывать по

Дополнительная информация

Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1829870libvncserver: integer overflow and heap-based buffer overflow in libvncclient/cursor.c in HandleCursorShape function

0 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.

CVSS3: 9.8
nvd
больше 6 лет назад

libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.

CVSS3: 9.8
debian
больше 6 лет назад

libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCurso ...

CVSS3: 9.8
github
больше 4 лет назад

libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.

suse-cvrf
больше 6 лет назад

Security update for LibVNCServer

0 Low

CVSS3