Unrated severityNVD Advisory· Published Sep 30, 2014· Updated May 6, 2026
CVE-2014-6051
CVE-2014-6051
Description
Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow.
Affected products
7- cpe:2.3:o:redhat:enterprise_linux_server_aus:6.5:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_eus:6.5.z:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
17- www.ocert.org/advisories/ocert-2014-007.htmlnvdPatchThird Party AdvisoryUS Government Resource
- github.com/newsoft/libvncserver/commit/045a044e8ae79db9244593fbce154cdf6e843273nvdPatchThird Party Advisory
- lists.fedoraproject.org/pipermail/package-announce/2014-October/139654.htmlnvdThird Party Advisory
- lists.fedoraproject.org/pipermail/package-announce/2014-September/139445.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2015-0113.htmlnvdThird Party Advisory
- seclists.org/oss-sec/2014/q3/639nvdThird Party Advisory
- secunia.com/advisories/61506nvdPermissions RequiredThird Party Advisory
- www.debian.org/security/2014/dsa-3081nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2014/09/25/11nvdThird Party Advisory
- www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlnvdThird Party Advisory
- www.kde.org/info/security/advisory-20140923-1.txtnvdThird Party Advisory
- lists.opensuse.org/opensuse-updates/2015-12/msg00022.htmlnvd
- www.securityfocus.com/bid/70093nvd
- lists.debian.org/debian-lts-announce/2019/10/msg00042.htmlnvd
- security.gentoo.org/glsa/201507-07nvd
- security.gentoo.org/glsa/201612-36nvd
- usn.ubuntu.com/4587-1/nvd
News mentions
0No linked articles in our index yet.