CVE-2016-10207: Buffer Overflow
A vulnerability was found in tigerVNC. The Xvnc server from tigervnc can crash when a client terminates a TLS connection early. This is due to invalid initialization/deinitialization order of the GnuTLS library.
References:
http://seclists.org/oss-sec/2017/q1/297
Upstream patch:
https://github.com/TigerVNC/tigervnc/commit/8aa4bc53206c2430bbf0c8f4b642f59a379ee649
Other sources
The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10207?
CVE-2016-10207 is classified as a medium severity vulnerability due to the potential for causing a crash.
How does CVE-2016-10207 affect TigerVNC?
CVE-2016-10207 affects TigerVNC by causing the Xvnc server to crash when a client terminates a TLS connection prematurely.
What versions of TigerVNC are affected by CVE-2016-10207?
CVE-2016-10207 affects TigerVNC versions 0.0.90, 0.0.91, 1.0, 1.0.1, 1.1.0, 1.3, 1.3.1, and 1.7.
How do I fix CVE-2016-10207?
To fix CVE-2016-10207, upgrade to a patched version of TigerVNC that addresses the initialization order issue with GnuTLS.
What should I do if I am using openSUSE and have CVE-2016-10207?
If you are using openSUSE, you should upgrade your system packages to obtain the security updates that mitigate CVE-2016-10207.