In TigerVNC 1.7.1 (CConnection.cxx CConnection::CConnection), an unauthenticated client can cause a small memory leak in the server.
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
Link | Tags |
---|---|
https://github.com/TigerVNC/tigervnc/pull/436 | issue tracking third party advisory patch |
https://github.com/TigerVNC/tigervnc/pull/436/commits/dccb5f7d776e93863ae10bbff56a45c523c6eeb0 | issue tracking third party advisory patch |
https://access.redhat.com/errata/RHSA-2017:2000 | vendor advisory |
http://www.securityfocus.com/bid/97305 | vdb entry |
https://security.gentoo.org/glsa/201801-13 | vendor advisory |