scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user. References: https://github.com/LibVNC/x11vnc/commit/69eeb9f7baa14ca03b16c9de821f9876def7a36a https://lists.debian.org/debian-lts-announce/2020/12/msg00018.html https://www.debian.org/security/2020/dsa-4799
Created x11vnc tracking bugs for this issue: Affects: epel-all [bug 1933604] Affects: fedora-all [bug 1933603]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.