In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2017:2000 | vendor advisory |
http://www.securityfocus.com/bid/97305 | vdb entry |
https://github.com/TigerVNC/tigervnc/pull/438 | patch third party advisory issue tracking |
https://security.gentoo.org/glsa/201801-13 | vendor advisory |