CVE-2014-6052
Publication date 24 September 2014
Last updated 26 May 2025
Ubuntu priority
Description
The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which allows remote VNC servers to cause a denial of service (application crash) or possibly execute arbitrary code by specifying a large screen size in a (1) FramebufferUpdate, (2) ResizeFrameBuffer, or (3) PalmVNCReSizeFrameBuffer message.
Status
| Package | Ubuntu Release | Status | 
|---|---|---|
| italc | 20.04 LTS focal | Not in release | 
| 18.04 LTS bionic | 
                              
                               
                                Fixed 1:3.0.1+dfsg1-1 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 16.04 LTS xenial | 
                              
                               
                                Fixed 1:2.0.2+dfsg1-4ubuntu0.1 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 14.04 LTS trusty | Not in release | |
| krfb | 14.04 LTS trusty | Not in release | 
| libvncserver | 14.04 LTS trusty | 
                              
                               
                                Fixed 0.9.9+dfsg-1ubuntu1.1 
                                
                               
                             |      
                          
                            
                          
                        
                      
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2365-1
 - LibVNCServer vulnerabilities
 - 29 September 2014
 - USN-4587-1
 - iTALC vulnerabilities
 - 20 October 2020