Bugzilla – Bug 1173878
VUL-0: CVE-2020-14396: LibVNCServer: NULL pointer dereference in tls_openssl.c
Last modified: 2020-08-27 13:55:01 UTC
CVE-2020-14396 An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.c has a NULL pointer dereference. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-14396 http://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-14396.html https://github.com/LibVNC/libvncserver/commit/33441d90a506d5f3ae9388f2752901227e430553 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14396 https://github.com/LibVNC/libvncserver/compare/LibVNCServer-0.9.12...LibVNCServer-0.9.13
In 11,12,15/LibVNCServer, code not found, considering not affected. TW already fixed by version update.
Submitted for 15,12/LibVNCServer. I believe all fixed.
Done