An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"89223639384740056327633360190699813562",
"247750316289086952643248309325503627435",
"272598481191648168756492052067410401352",
"176189432925519699138405263611716047346",
"165114043731271655018390940198517944275",
"227678021181733996754695317892915777790",
"25517129005542970557011804220768259493"
]
},
"signature_type": "Line",
"target": {
"file": "libvncclient/rfbproto.c"
},
"deprecated": false,
"source": "https://github.com/libvnc/libvncserver/commit/8937203441ee241c4ace85da687b7d6633a12365",
"signature_version": "v1",
"id": "CVE-2020-14405-ab6a7402"
},
{
"digest": {
"length": 15741.0,
"function_hash": "120056847109929900322733339222930740819"
},
"signature_type": "Function",
"target": {
"function": "HandleRFBServerMessage",
"file": "libvncclient/rfbproto.c"
},
"deprecated": false,
"source": "https://github.com/libvnc/libvncserver/commit/8937203441ee241c4ace85da687b7d6633a12365",
"signature_version": "v1",
"id": "CVE-2020-14405-ca65def6"
}
]