CVE-2014-6055Improper Restriction of Operations within the Bounds of a Memory Buffer in Libvncserver

Severity
6.5MEDIUMNVD
OSV7.5
EPSS
11.2%
top 6.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 30
Latest updateMay 13

Description

Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) directory name or the (3) FileTime attribute in a rfbFileTransferOffer message.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages4 packages

debiandebian/libvncserver< libvncserver 0.9.9+dfsg-6.1 (bookworm)
Debianlibvncserver_project/libvncserver< 0.9.9+dfsg-6.1+3
Ubuntulibvncserver_project/libvncserver< 0.9.9+dfsg-1ubuntu1.1

Also affects: Debian Linux 7.0, Fedora 20, 21, Enterprise Linux 6.5, 6.5.z

Patches

🔴Vulnerability Details

4
GHSA
GHSA-ggwh-wx55-84cx: Multiple stack-based buffer overflows in the File Transfer feature in rfbserver2022-05-13
OSV
italc vulnerabilities2020-10-20
OSV
CVE-2014-6055: Multiple stack-based buffer overflows in the File Transfer feature in rfbserver2014-09-30
OSV
libvncserver vulnerabilities2014-09-29

📋Vendor Advisories

4
Ubuntu
iTALC vulnerabilities2020-10-20
Ubuntu
LibVNCServer vulnerabilities2014-09-29
Red Hat
libvncserver: server stacked-based buffer overflow flaws in file transfer handling2014-09-23
Debian
CVE-2014-6055: libvncserver - Multiple stack-based buffer overflows in the File Transfer feature in rfbserver....2014

💬Community

5
Bugzilla
CVE-2014-6051 CVE-2014-6053 CVE-2014-6052 CVE-2014-6055 CVE-2014-6054 krfb: various flaws [fedora-all]2014-09-24
Bugzilla
CVE-2014-6051 CVE-2014-6053 CVE-2014-6052 CVE-2014-6055 CVE-2014-6054 libvncserver: various flaws [fedora-all]2014-09-24
Bugzilla
CVE-2014-6051 CVE-2014-6053 CVE-2014-6052 CVE-2014-6055 CVE-2014-6054 libvncserver: various flaws [epel-5]2014-09-24
Bugzilla
CVE-2014-6051 CVE-2014-6053 CVE-2014-6052 CVE-2014-6055 libvncserver: various flaws [epel-7]2014-09-24
Bugzilla
CVE-2014-6055 libvncserver: server stacked-based buffer overflow flaws in file transfer handling2014-09-19
CVE-2014-6055 — Debian Libvncserver vulnerability | cvebase