CVE-2019-20839
published 2020-06-17CVE-2019-20839: libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libvncserver | < libvncserver 0.9.13+dfsg-1 (bookworm) | libvncserver 0.9.13+dfsg-1 (bookworm) |
| libvnc_project | libvncserver | <= 0.9.12 | — |
| libvncserver_project | libvncserver | >= 0 < 0.9.13+dfsg-1 | 0.9.13+dfsg-1 |
| libvncserver_project | libvncserver | >= 0 < 0.9.13+dfsg-1 | 0.9.13+dfsg-1 |
| libvncserver_project | libvncserver | >= 0 < 0.9.13+dfsg-1 | 0.9.13+dfsg-1 |
| libvncserver_project | libvncserver | >= 0 < 0.9.13+dfsg-1 | 0.9.13+dfsg-1 |
| libvncserver_project | libvncserver | >= 0 < 0.9.10+dfsg-3ubuntu0.16.04.5 | 0.9.10+dfsg-3ubuntu0.16.04.5 |
| libvncserver_project | libvncserver | >= 0 < 0.9.11+dfsg-1ubuntu1.3 | 0.9.11+dfsg-1ubuntu1.3 |
| libvncserver_project | libvncserver | >= 0 < 0.9.12+dfsg-9ubuntu0.2 | 0.9.12+dfsg-9ubuntu0.2 |
| opensuse | leap | — | — |
| siemens | simatic_itc1500_firmware | >= 3.0.0.0 < 3.2.1.0 | 3.2.1.0 |
| siemens | simatic_itc1500_pro_firmware | >= 3.0.0.0 < 3.2.1.0 | 3.2.1.0 |
| siemens | simatic_itc1900_firmware | >= 3.0.0.0 < 3.2.1.0 | 3.2.1.0 |
| siemens | simatic_itc1900_pro_firmware | >= 3.0.0.0 < 3.2.1.0 | 3.2.1.0 |
| siemens | simatic_itc2200_firmware | >= 3.0.0.0 < 3.2.1.0 | 3.2.1.0 |
| siemens | simatic_itc2200_pro_firmware | >= 3.0.0.0 < 3.2.1.0 | 3.2.1.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH