Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 26 tigervnc Security Advisory Critical: Memory Leaks and More

fedora
Calendar Grey April 11, 2017
Dist Fedora Esm H88
Crucial security patch for tigervnc addresses multiple vulnerabilities in Fedora 26 to enhance system protection and performance.
Security fix for CVE-2017-7392 CVE-2017-7393 CVE-2017-7394 CVE-2017-7395 CVE-2017-7396

Summary

Virtual Network Computing (VNC) is a remote display system which

allows you to view a computing 'desktop' environment not only on the

machine where it is running, but from anywhere on the Internet and

from a wide variety of machine architectures. This package contains a

client which will allow you to connect to other desktops running a VNC

server.

Security fix for CVE-2017-7392 CVE-2017-7393 CVE-2017-7394 CVE-2017-7395

CVE-2017-7396. Add systemd unit file for Xvnc.

[ 1 ] Bug #1438703 - CVE-2017-7396 tigervnc: SecurityServer and ClientServer memory leaks

https://bugzilla.redhat.com/show_bug.cgi?id=1438703

[ 2 ] Bug #1438701 - CVE-2017-7395 tigervnc: Integer overflow in SMsgReader::readClientCutText

https://bugzilla.redhat.com/show_bug.cgi?id=1438701

[ 3 ] Bug #1438700 - CVE-2017-7394 tigervnc: Server crash via long usernames

https://bugzilla.redhat.com/show_bug.cgi?id=1438700

[ 4 ] Bug #1438697 - CVE-2017-7393 tigervnc: Double free via crafted fences

https://bugzilla.redhat.com/show_bug.cgi?id=1438697

[ 5 ] Bug #1438694 - CVE-2017-7392 tigervnc: SSecurityVeNCrypt memory leak

https://bugzilla.redhat.com/show_bug.cgi?id=1438694

su -c 'dnf upgrade tigervnc' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 26
Version: 1.7.1
Release: 4.fc26
Summary: A TigerVNC remote display system

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here