Vulnerability CVE-2020-29260: Information

Description

libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: Sept. 3, 2022
Modified: Oct. 5, 2022
Error type identifier: CWE-400

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libvncserversisyphus0.9.13-alt30.9.14-alt1ALT-PU-2022-2923-1309018Fixed
libvncserversisyphus_e2k0.9.13-alt30.9.14-alt1ALT-PU-2022-6961-1-Fixed
libvncserversisyphus_riscv640.9.13-alt30.9.14-alt1ALT-PU-2022-6805-1-Fixed
libvncserversisyphus_loongarch640.9.14-alt10.9.14-alt1ALT-PU-2024-1443-1-Fixed
libvncserverp100.9.13-alt30.9.14-alt1ALT-PU-2022-3020-1309026Fixed
libvncserverp10_e2k0.9.13-alt30.9.14-alt1ALT-PU-2022-6958-1-Fixed
libvncserverc10f10.9.13-alt30.9.13-alt3ALT-PU-2022-3020-1309026Fixed
libvncserverc9f20.9.13-alt30.9.13-alt3ALT-PU-2022-2962-1309027Fixed
libvncserverp110.9.13-alt30.9.14-alt1ALT-PU-2022-2923-1309018Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:libvncserver_project:libvncserver:0.9.13:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*