libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.
{ "vanir_signatures": [ { "target": { "file": "libvncclient/sockets.c" }, "id": "CVE-2019-20839-05ce48f7", "source": "https://github.com/libvnc/libvncserver/commit/3fd03977c9b35800d73a865f167338cb4d05b0c1", "digest": { "line_hashes": [ "52876093981780426855339000577121701361", "219712199165541620599692929659710770492", "171295154040440005142750223507192156157", "335200676590474681522118523928735727245" ], "threshold": 0.9 }, "signature_version": "v1", "signature_type": "Line", "deprecated": false }, { "target": { "function": "ConnectClientToUnixSock", "file": "libvncclient/sockets.c" }, "id": "CVE-2019-20839-ec50ec35", "source": "https://github.com/libvnc/libvncserver/commit/3fd03977c9b35800d73a865f167338cb4d05b0c1", "digest": { "length": 609.0, "function_hash": "141014285350177029189592347789716145813" }, "signature_version": "v1", "signature_type": "Function", "deprecated": false } ] }