CVE-2019-20788
23.04.2020, 19:15
libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.Enginsight
| Vendor | Product | Version |
|---|---|---|
| libvnc_project | libvncserver | 𝑥 ≤ 0.9.12 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| siemens | simatic_itc1500_firmware | 3.0.0.0 ≤ 𝑥 < 3.2.1.0 |
| siemens | simatic_itc1500_pro_firmware | 3.0.0.0 ≤ 𝑥 < 3.2.1.0 |
| siemens | simatic_itc1900_firmware | 3.0.0.0 ≤ 𝑥 < 3.2.1.0 |
| siemens | simatic_itc1900_pro_firmware | 3.0.0.0 ≤ 𝑥 < 3.2.1.0 |
| siemens | simatic_itc2200_firmware | 3.0.0.0 ≤ 𝑥 < 3.2.1.0 |
| siemens | simatic_itc2200_pro_firmware | 3.0.0.0 ≤ 𝑥 < 3.2.1.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libvncserver |
| ||||||||||||||||||||||||||
| x11vnc |
|
References