Bugzilla – Bug 1173698
VUL-0: CVE-2020-14405: LibVNCServer: libvncclient/rfbproto.c does not limit TextChat size.
Last modified: 2020-07-03 14:58:14 UTC
CVE-2020-14405 An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-14405 http://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-14405.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14405 https://github.com/LibVNC/libvncserver/compare/LibVNCServer-0.9.12...LibVNCServer-0.9.13 https://github.com/LibVNC/libvncserver/commit/8937203441ee241c4ace85da687b7d6633a12365 https://lists.debian.org/debian-lts-announce/2020/06/msg00035.html
We previously tracked this issue as CVE-2019-20788 and it is already fixed in all of our code-streams. *** This bug has been marked as a duplicate of bug 1170441 ***