CVE-2017-7395: Integer Overflow
In TigerVNC (SMsgReader.cxx SMsgReader::readClientCutText), an authenticated client can crash the server by causing an integer overflow.
Upstream patch:
https://github.com/TigerVNC/tigervnc/pull/436/commits/bf3bdac082978ca32895a4b6a123016094905689
Other sources
In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TigerVNCto a version that resolves this vulnerability.Fixed in 1.7.1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7395?
CVE-2017-7395 is categorized as a vulnerability that can allow an authenticated client to crash the TigerVNC server.
How do I fix CVE-2017-7395?
To fix CVE-2017-7395, users should update TigerVNC to version 1.7.2 or later, which includes the necessary patches.
What versions of TigerVNC are affected by CVE-2017-7395?
CVE-2017-7395 affects TigerVNC version 1.7.1.
Can CVE-2017-7395 be exploited remotely?
CVE-2017-7395 requires an authenticated client, meaning exploitation can occur only from users with access to the server.
What are the consequences of CVE-2017-7395?
The main consequence of CVE-2017-7395 is a denial of service, as it allows an authenticated client to crash the TigerVNC server.