High severity7.5NVD Advisory· Published Jun 17, 2020· Updated Jun 17, 2026
CVE-2020-14396
CVE-2020-14396
Description
An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.c has a NULL pointer dereference.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 5 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
- cpe:2.3:o:siemens:simatic_itc1500_firmware:*:*:*:*:*:*:*:*Range: >=3.0.0.0,<3.2.1.0
- cpe:2.3:o:siemens:simatic_itc1500_pro_firmware:*:*:*:*:*:*:*:*Range: >=3.0.0.0,<3.2.1.0
- cpe:2.3:o:siemens:simatic_itc1900_firmware:*:*:*:*:*:*:*:*Range: >=3.0.0.0,<3.2.1.0
- cpe:2.3:o:siemens:simatic_itc1900_pro_firmware:*:*:*:*:*:*:*:*Range: >=3.0.0.0,<3.2.1.0
- cpe:2.3:o:siemens:simatic_itc2200_firmware:*:*:*:*:*:*:*:*Range: >=3.0.0.0,<3.2.1.0
- cpe:2.3:o:siemens:simatic_itc2200_pro_firmware:*:*:*:*:*:*:*:*Range: >=3.0.0.0,<3.2.1.0
- LibVNCServer/LibVNCServerdescription
- Range: <0.9.13
Patches
Vulnerability mechanics
References
4- cert-portal.siemens.com/productcert/pdf/ssa-390195.pdfnvdPatchThird Party Advisory
- github.com/LibVNC/libvncserver/commit/33441d90a506d5f3ae9388f2752901227e430553nvdPatchThird Party Advisory
- github.com/LibVNC/libvncserver/compare/LibVNCServer-0.9.12...LibVNCServer-0.9.13nvdRelease NotesThird Party Advisory
- usn.ubuntu.com/4434-1/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.