{"id":"CVE-2020-29074","details":"scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user.","modified":"2026-07-09T00:37:10.788481Z","published":"2020-11-25T23:15:11.300Z","related":["openSUSE-SU-2024:11496-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"},{"introduced":"10.0"},{"last_affected":"10.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"},{"cpes":["cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"32"},{"last_affected":"32"},{"introduced":"33"},{"last_affected":"33"},{"introduced":"34"},{"last_affected":"34"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H2FLWSVH32O6JXLRQBYDQLP7XRSTLUPQ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MHVXHZE3YIP4RTWGQ24IDBSW44XPRDOC/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZL6NQTNK5PT63D2JX5YVV5OLUL76S5C/"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2020/12/msg00018.html"},{"type":"ADVISORY","url":"https://www.debian.org/security/2020/dsa-4799"},{"type":"FIX","url":"https://github.com/LibVNC/x11vnc/commit/69eeb9f7baa14ca03b16c9de821f9876def7a36a"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libvnc/x11vnc","events":[{"introduced":"4ca006fed80410bd9b061a1519bd5d9366bb0bc8"},{"last_affected":"4ca006fed80410bd9b061a1519bd5d9366bb0bc8"},{"fixed":"69eeb9f7baa14ca03b16c9de821f9876def7a36a"}],"database_specific":{"cpe":"cpe:2.3:a:x11vnc_project:x11vnc:0.9.16:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.9.16"},{"last_affected":"0.9.16"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["0.9.16"],"database_specific":{"vanir_signatures_modified":"2026-07-09T00:37:10Z","vanir_signatures":[{"id":"CVE-2020-29074-16496eb1","signature_type":"Line","signature_version":"v1","source":"https://github.com/libvnc/x11vnc/commit/69eeb9f7baa14ca03b16c9de821f9876def7a36a","target":{"file":"src/scan.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["56740894291832566308400293842992874083","35125186519063144221375988472889355695","20298482367566999856091248652949110519","126259484339115188972053899482603857563"]}},{"source":"https://github.com/libvnc/x11vnc/commit/69eeb9f7baa14ca03b16c9de821f9876def7a36a","target":{"file":"src/scan.c","function":"shm_create"},"deprecated":false,"digest":{"function_hash":"105144691058749000443747703101666032586","length":2481},"id":"CVE-2020-29074-32a2291b","signature_type":"Function","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-29074.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}