First published: Tue Apr 04 2017(Updated: )
In TigerVNC (CConnection.cxx CConnection::CConnection), an unauthenticated client can cause a small memory leak in the server. Upstream patch: <a href="https://github.com/TigerVNC/tigervnc/pull/436/commits/dccb5f7d776e93863ae10bbff56a45c523c6eeb0">https://github.com/TigerVNC/tigervnc/pull/436/commits/dccb5f7d776e93863ae10bbff56a45c523c6eeb0</a>
Affected Software | Affected Version | How to fix |
---|---|---|
TigerVNC |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1438703 is classified as low due to a small memory leak that can be exploited by an unauthenticated client.
To resolve REDHAT-BUG-1438703, apply the upstream patch provided in the TigerVNC GitHub repository.
Users running vulnerable versions of TigerVNC are affected by the memory leak issue described in REDHAT-BUG-1438703.
REDHAT-BUG-1438703 is categorized as a memory leak vulnerability due to the behavior of unauthenticated clients connecting to the TigerVNC server.
Currently, there is no documented workaround for REDHAT-BUG-1438703 other than applying the patch.