scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user.
References
Link | Resource |
---|---|
https://github.com/LibVNC/x11vnc/commit/69eeb9f7baa14ca03b16c9de821f9876def7a36a | Patch Third Party Advisory |
https://www.debian.org/security/2020/dsa-4799 | Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2020/12/msg00018.html | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MHVXHZE3YIP4RTWGQ24IDBSW44XPRDOC/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H2FLWSVH32O6JXLRQBYDQLP7XRSTLUPQ/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PZL6NQTNK5PT63D2JX5YVV5OLUL76S5C/ | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2020-11-25 15:15
Updated : 2021-07-21 04:39
NVD link : CVE-2020-29074
Mitre link : CVE-2020-29074
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
debian
- debian_linux
fedoraproject
- fedora
x11vnc_project
- x11vnc