First published: Sat Apr 01 2017(Updated: )
In TigerVNC (CConnection.cxx CConnection::CConnection), an unauthenticated client can cause a small memory leak in the server. Upstream patch: <a href="https://github.com/TigerVNC/tigervnc/pull/436/commits/dccb5f7d776e93863ae10bbff56a45c523c6eeb0">https://github.com/TigerVNC/tigervnc/pull/436/commits/dccb5f7d776e93863ae10bbff56a45c523c6eeb0</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tigervnc | =1.7.1 |
https://github.com/TigerVNC/tigervnc/pull/436/commits/dccb5f7d776e93863ae10bbff56a45c523c6eeb0
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7396 has been classified as a minor issue due to the memory leak being relatively small.
To fix CVE-2017-7396, update to a patched version of TigerVNC where the memory leak has been addressed.
CVE-2017-7396 specifically affects TigerVNC version 1.7.1.
Yes, CVE-2017-7396 can be exploited by an unauthenticated client connecting to the server.
No, CVE-2017-7396 is not considered a critical vulnerability because it leads only to a small memory leak without compromising the server's security.