REDHAT-BUG-1438694: Low severity tigervnc vulnerability
Published Apr 4, 2017
·Updated
In TigerVNC (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server.
Upstream patch:
https://github.com/TigerVNC/tigervnc/pull/441/commits/8f3e8663b3cf57c0b62d939d6953fbfcc112aadd
Affected Software
1 affected component
TigerVNC TigerVNC
Event History
Apr 4, 2017
Data Sourced
via Red Hat·08:39 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1438694?
The severity of REDHAT-BUG-1438694 is considered low as it results in a small memory leak.
2
How do I fix REDHAT-BUG-1438694?
To fix REDHAT-BUG-1438694, you should apply the upstream patch from TigerVNC.
3
Which versions of TigerVNC are affected by REDHAT-BUG-1438694?
All versions of TigerVNC are affected by REDHAT-BUG-1438694.
4
Can exploit of REDHAT-BUG-1438694 lead to data loss?
Exploitation of REDHAT-BUG-1438694 does not lead to data loss but can cause a memory leak.
5
Is authentication required to exploit REDHAT-BUG-1438694?
No, an unauthenticated client can exploit REDHAT-BUG-1438694.