CVE-2014-6055

medium
Published 2014-09-30 · Modified 2026-05-06
CVSS v3
CVSS v2
6.5
VIR risk
6.5

Description

Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) directory name or the (3) FileTime attribute in a rfbFileTransferOffer message.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-6055

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.kde.org/info/security/advisory-20140923-1.txt

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/newsoft/libvncserver/commit/f528072216dec01cee7ca35d94e171a3b909e677

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/newsoft/libvncserver/commit/06ccdf016154fde8eccb5355613ba04c59127b2e

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.9.9+dfsg-6.1
debian debianbullseyefixed0.9.9+dfsg-6.1
debian debianforkyfixed0.9.9+dfsg-6.1
debian debiansidfixed0.9.9+dfsg-6.1
debian debiantrixiefixed0.9.9+dfsg-6.1
fedora fedora20affected
fedora fedora21affected
debian debian7.0affected

Application impact

VendorProductVersionsFixed
libvncserverlibvncserver{"endIncluding":"0.9.9"}

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.