Back

HIGH

realvnc: Null pointer dereference flaw in ClientCutText message handling

Published Feb 5, 2020

Description

A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A remote attacker could use this flaw to crash the VNC server by sending a specially crafted ClientCutText message from a VNC client.

Affected products

Remediation

Red Hat statement

This flaw is in RealVNC shipped with Red Hat Enterprise Linux 5. A similar flaw was also found in LibVNCServer and was assigned CVE-2014-6053

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 5, 2020
Updated Aug 7, 2024
Reserved Sep 2, 2014
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Sep 23, 2014