First published: Sat Apr 01 2017(Updated: )
In TigerVNC (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server. Upstream patch: <a href="https://github.com/TigerVNC/tigervnc/pull/441/commits/8f3e8663b3cf57c0b62d939d6953fbfcc112aadd">https://github.com/TigerVNC/tigervnc/pull/441/commits/8f3e8663b3cf57c0b62d939d6953fbfcc112aadd</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TigerVNC | =1.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7392 is classified as a moderate severity vulnerability affecting TigerVNC.
To fix CVE-2017-7392, upgrade your TigerVNC installation to version 1.7.2 or later.
CVE-2017-7392 is a memory leak vulnerability that can be triggered by an unauthenticated client.
TigerVNC version 1.7.1 is specifically affected by CVE-2017-7392.
While CVE-2017-7392 causes a memory leak, it does not allow for unauthorized access or severe system compromise.