VYPR
Unrated severityNVD Advisory· Published Jun 17, 2020· Updated Aug 4, 2024

CVE-2020-14397

CVE-2020-14397

Description

An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A NULL pointer dereference in LibVNCServer's rfbregion.c allows remote attackers to cause a denial of service via crafted region clipping.

Vulnerability

LibVNCServer before version 0.9.13 contains a NULL pointer dereference in libvncserver/rfbregion.c, triggered during region clipping operations. [1][2]

Exploitation

A remote attacker can send crafted RFB messages to trigger the NULL pointer dereference, causing the server to crash. No authentication is required. [1][2]

Impact

Successful exploitation results in a denial of service via server crash. No other impacts have been disclosed. [1][2]

Mitigation

Upgrade to LibVNCServer 0.9.13 or later. For Ubuntu systems, the fix is included in USN-4434-1 (for libvncserver) and USN-4573-1 (for Vino). [1][2]

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

30

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.