CVE-2014-6051
Publication date 24 September 2014
Last updated 24 July 2024
Ubuntu priority
Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow.
Status
Package | Ubuntu Release | Status |
---|---|---|
italc | 20.04 LTS focal | Not in release |
18.04 LTS bionic |
Fixed 1:3.0.1+dfsg1-1
|
|
16.04 LTS xenial |
Fixed 1:2.0.2+dfsg1-4ubuntu0.1
|
|
14.04 LTS trusty | Not in release | |
krfb | 14.04 LTS trusty | Not in release |
libvncserver | 14.04 LTS trusty |
Fixed 0.9.9+dfsg-1ubuntu1.1
|
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2365-1
- LibVNCServer vulnerabilities
- 29 September 2014
- USN-4587-1
- iTALC vulnerabilities
- 20 October 2020