REDHAT-BUG-1438701: Integer Overflow
Published Apr 4, 2017
·Updated
In TigerVNC (SMsgReader.cxx SMsgReader::readClientCutText), an authenticated client can crash the server by causing an integer overflow.
Upstream patch:
https://github.com/TigerVNC/tigervnc/pull/436/commits/bf3bdac082978ca32895a4b6a123016094905689
Affected Software
1 affected component
TigerVNC TigerVNC
Event History
Apr 4, 2017
Data Sourced
via Red Hat·08:48 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1438701?
The severity of REDHAT-BUG-1438701 is typically classified as moderate due to the potential for a server crash.
2
How do I fix REDHAT-BUG-1438701?
To fix REDHAT-BUG-1438701, apply the upstream patches available for TigerVNC as indicated in the official repository.
3
What systems are affected by REDHAT-BUG-1438701?
REDHAT-BUG-1438701 specifically affects the TigerVNC server.
4
Can an unauthenticated user exploit REDHAT-BUG-1438701?
No, only authenticated clients can exploit the vulnerability described in REDHAT-BUG-1438701.
5
Is there a workaround for REDHAT-BUG-1438701 until a patch is applied?
Currently, there are no documented workarounds for REDHAT-BUG-1438701, so updating to the patched version is recommended.