libvncserver.so is vulnerable to denial of service(DoS) attack. The issue exists as an out-of-bounds access from the encoding function in libvncserver/corre.c
.
cert-portal.siemens.com/productcert/pdf/ssa-390195.pdf
github.com/LibVNC/libvncserver/commit/74e8a70f2c9a5248d6718ce443e07c7ed314
github.com/LibVNC/libvncserver/commit/74e8a70f2c9a5248d6718ce443e07c7ed314dfff
github.com/LibVNC/libvncserver/compare/LibVNCServer-0.9.12...LibVNCServer-0.9.13
lists.debian.org/debian-lts-announce/2020/06/msg00035.html
lists.debian.org/debian-lts-announce/2020/08/msg00045.html
usn.ubuntu.com/4434-1/
usn.ubuntu.com/4573-1/