REDHAT-BUG-1418761: Medium severity tigervnc vulnerability
A vulnerability was found in tigerVNC. The Xvnc server from tigervnc can crash when a client terminates a TLS connection early. This is due to invalid initialization/deinitialization order of the GnuTLS library.
References:
http://seclists.org/oss-sec/2017/q1/297
Upstream patch:
https://github.com/TigerVNC/tigervnc/commit/8aa4bc53206c2430bbf0c8f4b642f59a379ee649
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1418761?
The severity of REDHAT-BUG-1418761 is classified as high, as it can lead to crashes of the Xvnc server.
How do I fix REDHAT-BUG-1418761?
To fix REDHAT-BUG-1418761, you should update to the latest version of TigerVNC that addresses the TLS termination issue.
Which software is affected by REDHAT-BUG-1418761?
REDHAT-BUG-1418761 affects the TigerVNC software, specifically the Xvnc server component.
What causes the vulnerability in REDHAT-BUG-1418761?
The vulnerability in REDHAT-BUG-1418761 is caused by the invalid initialization and deinitialization order of the GnuTLS library.
Can REDHAT-BUG-1418761 affect server stability?
Yes, REDHAT-BUG-1418761 can adversely affect server stability by causing the Xvnc server to crash when a client disconnects abruptly.