In TigerVNC 1.7.1 (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server.
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2017:2000 | vendor advisory |
https://github.com/TigerVNC/tigervnc/pull/441 | issue tracking third party advisory patch |
http://www.securityfocus.com/bid/97305 | vdb entry |
https://security.gentoo.org/glsa/201801-13 | vendor advisory |