buildroot ▾
›
master ▾
›
vulnerability
›
CVE-2020-29074
Component Overview
Vulnerability Overview
Name
CVE-2020-29074
Source
NVD (
link
)
Debian (
link
)
Description
scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user.
CWEs
CWE-732
Published Date
Nov 25, 2020
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/LibVNC/x11vnc/commit/69eeb9f7baa14ca03b16c9de821f9876def7a36a
Patch
https://lists.debian.org/debian-lts-announce/2020/12/msg00018.html
Mailing List
https://www.debian.org/security/2020/dsa-4799
Third Party Advisory
https://github.com/LibVNC/x11vnc/commit/69eeb9f7baa14ca03b16c9de821f9876def7a36a
Patch
https://lists.debian.org/debian-lts-announce/2020/12/msg00018.html
Mailing List
https://www.debian.org/security/2020/dsa-4799
Third Party Advisory
Analysis
#
Affected Component
Analysis
x11vnc
Patched
Vulnerability Ratings
#
8.8
CVSSv31
6.5
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
x11vnc
buildroot
2025.02.x
0.9.16
Patched
x11vnc
yocto
kirkstone
0.9.16+gitX
Not Affected
x11vnc
yocto
master
0.9.16+git
Not Affected
x11vnc
yocto
scarthgap
0.9.16+git
Not Affected
Resolved with patches
#
x11vnc (buildroot:2025.02.x)
#
Title
Author
Resolve
1
scan: limit access to shared memory segments to current user
=?UTF-8?q?Gu=C3=A9nal=20DAVALAN?= <guenal.davalan@uca.fr>
CVE-2020-29074
x11vnc (buildroot:master)
#
Title
Author
Resolve
1
scan: limit access to shared memory segments to current user
=?UTF-8?q?Gu=C3=A9nal=20DAVALAN?= <guenal.davalan@uca.fr>
CVE-2020-29074