RHSA-2024:0018: Important: tigervnc security update
Important: tigervnc security update
Other sources
Virtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients.Security Fix(es): xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions (CVE-2023-6377) xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty (CVE-2023-6478) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0018?
The severity of RHSA-2024:0018 is classified as important due to potential security vulnerabilities in the tigervnc package.
How do I fix RHSA-2024:0018?
To fix RHSA-2024:0018, update the tigervnc package to version 1.13.1-2.el8_9.4 or later.
What systems are affected by RHSA-2024:0018?
RHSA-2024:0018 affects Red Hat Enterprise Linux versions that utilize the tigervnc packages.
Is there a known exploit for RHSA-2024:0018?
There is no specific known exploit documented in relation to RHSA-2024:0018, but the vulnerabilities addressed can pose security risks.
What packages are included in the RHSA-2024:0018 update?
The RHSA-2024:0018 update includes several tigervnc packages, such as tigervnc-server, tigervnc-debuginfo, and tigervnc-selinux.