8.8
CVSSv3

CVE-2020-29074

Published: 25/11/2020 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

x11vnc project x11vnc 0.9.16

fedoraproject fedora 32

fedoraproject fedora 33

fedoraproject fedora 34

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #975875 x11vnc: CVE-2020-29074 Package: src:x11vnc; Maintainer for src:x11vnc is Debian Remote Maintainers <debian-remote@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 26 Nov 2020 05:03:01 UTC Severity: grave Tags: fixed-upstream, patch, security, upstrea ...
Guenal Davalan reported a flaw in x11vnc, a VNC server to allow remote access to an existing X session x11vnc creates shared memory segments with 0777 mode A local attacker can take advantage of this flaw for information disclosure, denial of service or interfering with the VNC session of another user on the host For the stable distribution (bus ...
scanc in x11vnc 0916 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user ...