REDHAT-BUG-1438700: Medium severity tigervnc vulnerability
In TigerVNC (SSecurityPlain.cxx SSecurityPlain::processMsg), unauthenticated users can crash the server by sending long usernames.
Upstream patches:
https://github.com/TigerVNC/tigervnc/pull/440/commits/62197c89e98be47a174074e4c7429c57767a4929 https://github.com/TigerVNC/tigervnc/pull/440/commits/9801c5efcf8c1774d9c807ebd5d27ac7049ad993
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1438700?
The severity of REDHAT-BUG-1438700 is high due to the potential for denial of service through server crashes.
How do I fix REDHAT-BUG-1438700?
To fix REDHAT-BUG-1438700, update TigerVNC to the latest patched version that addresses the long username vulnerability.
What impact does REDHAT-BUG-1438700 have on users?
REDHAT-BUG-1438700 allows unauthenticated users to crash the TigerVNC server by exploiting long usernames.
Is there a way to mitigate the effects of REDHAT-BUG-1438700?
Mitigation for REDHAT-BUG-1438700 involves configuring server settings to limit username lengths and restricting unauthenticated access.
What versions of TigerVNC are affected by REDHAT-BUG-1438700?
All versions of TigerVNC prior to the patch for REDHAT-BUG-1438700 are affected by this vulnerability.