First published: Thu Feb 02 2017(Updated: )
A vulnerability was found in tigerVNC. The Xvnc server from tigervnc can crash when a client terminates a TLS connection early. This is due to invalid initialization/deinitialization order of the GnuTLS library. References: <a href="http://seclists.org/oss-sec/2017/q1/297">http://seclists.org/oss-sec/2017/q1/297</a> Upstream patch: <a href="https://github.com/TigerVNC/tigervnc/commit/8aa4bc53206c2430bbf0c8f4b642f59a379ee649">https://github.com/TigerVNC/tigervnc/commit/8aa4bc53206c2430bbf0c8f4b642f59a379ee649</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE Leap | =42.1 | |
openSUSE Leap | =42.2 | |
Tigervnc Tigervnc | =0.0.90 | |
Tigervnc Tigervnc | =0.0.91 | |
Tigervnc Tigervnc | =1.0 | |
Tigervnc Tigervnc | =1.0.1 | |
Tigervnc Tigervnc | =1.1.0 | |
Tigervnc Tigervnc | =1.3 | |
Tigervnc Tigervnc | =1.3.1 | |
Tigervnc Tigervnc | =1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.