An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerability as there is no known path of exploitation or cross of a trust boundary
{
"isDisputed": true
}[
{
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2020-14400-70f37e3b",
"source": "https://github.com/libvnc/libvncserver/commit/53073c8d7e232151ea2ecd8a1243124121e10e2d",
"digest": {
"line_hashes": [
"27286812576839115884543175160988269078",
"126378025424545499359211745975564175189",
"94072546939175517512903866765638939671",
"142913035614552476143277396473228735757",
"16491202129239839746453209863899231208",
"329118107097954020458462031759542038328",
"139540123818845539957203460069661562707",
"262702335076891001489415279451883678023",
"268278606668869684054629684412740624732",
"190302750283181718757184748493504315953"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "libvncserver/translate.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2020-14400-bcfad6c4",
"source": "https://github.com/libvnc/libvncserver/commit/53073c8d7e232151ea2ecd8a1243124121e10e2d",
"digest": {
"length": 1002.0,
"function_hash": "53011332413877103642289004836945053853"
},
"signature_version": "v1",
"target": {
"file": "libvncserver/translate.c",
"function": "rfbSetClientColourMapBGR233"
}
}
]