REDHAT-BUG-1438703: Low severity tigervnc vulnerability
In TigerVNC (CConnection.cxx CConnection::CConnection), an unauthenticated client can cause a small memory leak in the server.
Upstream patch:
https://github.com/TigerVNC/tigervnc/pull/436/commits/dccb5f7d776e93863ae10bbff56a45c523c6eeb0
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1438703?
The severity of REDHAT-BUG-1438703 is classified as low due to a small memory leak that can be exploited by an unauthenticated client.
How do I fix REDHAT-BUG-1438703?
To resolve REDHAT-BUG-1438703, apply the upstream patch provided in the TigerVNC GitHub repository.
Who is affected by REDHAT-BUG-1438703?
Users running vulnerable versions of TigerVNC are affected by the memory leak issue described in REDHAT-BUG-1438703.
What type of vulnerability is REDHAT-BUG-1438703?
REDHAT-BUG-1438703 is categorized as a memory leak vulnerability due to the behavior of unauthenticated clients connecting to the TigerVNC server.
Is there a workaround for REDHAT-BUG-1438703?
Currently, there is no documented workaround for REDHAT-BUG-1438703 other than applying the patch.