7.5
CVSSv2

CVE-2014-6052

Published: 15/12/2014 Updated: 23/10/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and previous versions does not check certain malloc return values, which allows remote VNC servers to cause a denial of service (application crash) or possibly execute arbitrary code by specifying a large screen size in a (1) FramebufferUpdate, (2) ResizeFrameBuffer, or (3) PalmVNCReSizeFrameBuffer message.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libvncserver libvncserver

oracle solaris 11.3

debian debian linux 7.0

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

Vendor Advisories

Several security issues were fixed in LibVNCServer ...
Debian Bug report logs - #849478 tigervnc: CVE-2014-8241: NULL pointer dereference flaw in XRegion Package: src:tigervnc; Maintainer for src:tigervnc is TigerVNC Packaging Team <pkg-tigervnc-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 27 Dec 2016 16:09:02 UTC Sever ...
Debian Bug report logs - #762745 [CVE-2014-6051 to CVE-2014-6055] Multiple issues in libVNCserver Package: libvncserver; Maintainer for libvncserver is Peter Spiess-Knafl <dev@spiessknaflat>; Reported by: Luciano Bello <luciano@debianorg> Date: Wed, 24 Sep 2014 21:24:02 UTC Severity: grave Tags: patch, security Fi ...
Several vulnerabilities have been discovered in libvncserver, a library to implement VNC server functionality These vulnerabilities might result in the execution of arbitrary code or denial of service in both the client and the server side For the stable distribution (wheezy), these problems have been fixed in version 099+dfsg-1+deb7u1 For the ...
A NULL pointer dereference flaw was found in LibVNCServer's framebuffer setup A malicious VNC server could use this flaw to cause a VNC client to crash ...