REDHAT-BUG-1438697: Double Free
In TigerVNC (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to a crash of the TigerVNC server.
Upstream patch:
https://github.com/TigerVNC/tigervnc/pull/438/commits/f3afa24da144409a3c3a0e35913112583d987671
Upstream bug:
https://github.com/TigerVNC/tigervnc/issues/437
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1438697?
The severity of REDHAT-BUG-1438697 is considered moderate due to the potential for a crash of the TigerVNC server.
How do I fix REDHAT-BUG-1438697?
To fix REDHAT-BUG-1438697, apply the upstream patch provided by TigerVNC as detailed in their GitHub repository.
What does the vulnerability REDHAT-BUG-1438697 affect?
REDHAT-BUG-1438697 affects the TigerVNC software, specifically impacting the handling of authenticated client connections.
What type of attack does REDHAT-BUG-1438697 enable?
REDHAT-BUG-1438697 allows an authenticated client to trigger a double free vulnerability, resulting in a server crash.
Who is responsible for the TigerVNC vulnerability classified as REDHAT-BUG-1438697?
The vulnerability REDHAT-BUG-1438697 is attributed to the TigerVNC development team, who are responsible for maintaining and updating the software.