CVE-2017-7392: High severity TigerVNC TigerVNC vulnerability
In TigerVNC (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server.
Upstream patch:
https://github.com/TigerVNC/tigervnc/pull/441/commits/8f3e8663b3cf57c0b62d939d6953fbfcc112aadd
Other sources
In TigerVNC 1.7.1 (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TigerVNCto a version that resolves this vulnerability.Fixed in 1.7.1 - Operational
Apply the upstream patch referenced in the TigerVNC pull request commit 8f3e8663b3cf57c0b62d939d6953fbfcc112aadd, then restart the TigerVNC server to clear any leaked memory.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7392?
CVE-2017-7392 is classified as a moderate severity vulnerability affecting TigerVNC.
How do I fix CVE-2017-7392?
To fix CVE-2017-7392, upgrade your TigerVNC installation to version 1.7.2 or later.
What type of vulnerability is CVE-2017-7392?
CVE-2017-7392 is a memory leak vulnerability that can be triggered by an unauthenticated client.
Which version of TigerVNC is affected by CVE-2017-7392?
TigerVNC version 1.7.1 is specifically affected by CVE-2017-7392.
Can CVE-2017-7392 lead to any significant impact?
While CVE-2017-7392 causes a memory leak, it does not allow for unauthorized access or severe system compromise.