CVE-2014-8241: Null Pointer Dereference
This issue was discovered by Tim Waugh of Red Hat. Tigervnc is affected by same thing as in CVE-2014-6052. A NULL pointer dereference flaw was reported in tigervnc. A malicious VNC server could use this flaw to cause a client to crash.
Other sources
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8241?
CVE-2014-8241 has been classified as a medium severity vulnerability.
How do I fix CVE-2014-8241?
To fix CVE-2014-8241, you need to update the TigerVNC package to a version that addresses the NULL pointer dereference flaw.
Which software is affected by CVE-2014-8241?
CVE-2014-8241 affects multiple TigerVNC installations and specific versions of Red Hat Enterprise Linux 7.0.
What type of vulnerability is CVE-2014-8241?
CVE-2014-8241 is a NULL pointer dereference vulnerability that can lead to client crashes.
Can a malicious VNC server exploit CVE-2014-8241?
Yes, a malicious VNC server can exploit CVE-2014-8241 to crash the connected client.