An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.
{ "vanir_signatures": [ { "source": "https://github.com/libvnc/libvncserver/commit/8937203441ee241c4ace85da687b7d6633a12365", "deprecated": false, "target": { "file": "libvncclient/rfbproto.c" }, "signature_version": "v1", "digest": { "line_hashes": [ "89223639384740056327633360190699813562", "247750316289086952643248309325503627435", "272598481191648168756492052067410401352", "176189432925519699138405263611716047346", "165114043731271655018390940198517944275", "227678021181733996754695317892915777790", "25517129005542970557011804220768259493" ], "threshold": 0.9 }, "signature_type": "Line", "id": "CVE-2020-14405-ab6a7402" }, { "source": "https://github.com/libvnc/libvncserver/commit/8937203441ee241c4ace85da687b7d6633a12365", "deprecated": false, "target": { "file": "libvncclient/rfbproto.c", "function": "HandleRFBServerMessage" }, "signature_version": "v1", "digest": { "length": 15741.0, "function_hash": "120056847109929900322733339222930740819" }, "signature_type": "Function", "id": "CVE-2020-14405-ca65def6" } ] }