Lucene search

K
cveMitreCVE-2014-6055
HistorySep 30, 2014 - 4:55 p.m.

CVE-2014-6055

2014-09-3016:55:07
CWE-119
mitre
web.nvd.nist.gov
59
cve-2014-6055
buffer overflow
remote code execution
libvncserver
file transfer
denial of service
nvd

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

8.4

Confidence

High

EPSS

0.022

Percentile

89.5%

Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) directory name or the (3) FileTime attribute in a rfbFileTransferOffer message.

Affected configurations

Nvd
Node
fedoraprojectfedoraMatch20
OR
fedoraprojectfedoraMatch21
Node
debiandebian_linuxMatch7.0
Node
redhatenterprise_linux_server_ausMatch6.5
OR
redhatenterprise_linux_server_eusMatch6.5.z
Node
libvncserverlibvncserverRange0.9.9
VendorProductVersionCPE
fedoraprojectfedora21cpe:/o:fedoraproject:fedora:21:::
fedoraprojectfedora20cpe:/o:fedoraproject:fedora:20:::

References

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

8.4

Confidence

High

EPSS

0.022

Percentile

89.5%