CVE-2020-29074

Name
CVE-2020-29074
Description
scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://github.com/LibVNC/x11vnc/commit/69eeb9f7baa14ca03b16c9de821f9876def7a36a
Third Party Advisory https://www.debian.org/security/2020/dsa-4799
Mailing List https://lists.debian.org/debian-lts-announce/2020/12/msg00018.html
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MHVXHZE3YIP4RTWGQ24IDBSW44XPRDOC/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H2FLWSVH32O6JXLRQBYDQLP7XRSTLUPQ/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PZL6NQTNK5PT63D2JX5YVV5OLUL76S5C/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:x11vnc_project:x11vnc:0.9.16:*:*:*:*:*:*:* x11vnc == None == 0.9.16

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
x11vnc 3.13-community 0.9.16-r2 Tuan M. Hoang <tmhoang@flatglobe.org> fixed
x11vnc 3.14-community 0.9.16-r2 Tuan M. Hoang <tmhoang@flatglobe.org> fixed
x11vnc 3.15-community 0.9.16-r3 Tuan M. Hoang <tmhoang@flatglobe.org> fixed
x11vnc 3.16-community 0.9.16-r4 Tuan M. Hoang <tmhoang@flatglobe.org> fixed
x11vnc edge-community 0.9.16-r5 Tuan M. Hoang <tmhoang@flatglobe.org> fixed