CVE-2017-7396: High severity TigerVNC TigerVNC vulnerability
In TigerVNC (CConnection.cxx CConnection::CConnection), an unauthenticated client can cause a small memory leak in the server.
Upstream patch:
https://github.com/TigerVNC/tigervnc/pull/436/commits/dccb5f7d776e93863ae10bbff56a45c523c6eeb0
Other sources
In TigerVNC 1.7.1 (CConnection.cxx CConnection::CConnection), an unauthenticated client can cause a small memory leak in the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TigerVNCto a version that resolves this vulnerability.Fixed in 1.7.1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7396?
CVE-2017-7396 has been classified as a minor issue due to the memory leak being relatively small.
How do I fix CVE-2017-7396?
To fix CVE-2017-7396, update to a patched version of TigerVNC where the memory leak has been addressed.
What versions of TigerVNC are affected by CVE-2017-7396?
CVE-2017-7396 specifically affects TigerVNC version 1.7.1.
Can CVE-2017-7396 be exploited remotely?
Yes, CVE-2017-7396 can be exploited by an unauthenticated client connecting to the server.
Is CVE-2017-7396 a critical vulnerability?
No, CVE-2017-7396 is not considered a critical vulnerability because it leads only to a small memory leak without compromising the server's security.