Integer overflow in TigerVNC allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to screen size handling, which triggers a heap-based buffer overflow, a similar issue to CVE-2014-6051.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade tigervnc | Jul 30, 2024 | Oct 16, 2014 |
| Gentoo Linux | — | Upgrade net-misc/tigervnc. | Oct 30, 2017 | Oct 16, 2014 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.3.0.0.30.0 on Solaris 11.3Upgrade consolidation/X/X-incorporation to version 0.5.11-0.175.3.0.0.30.1483 on Solaris 11.3 | May 29, 2017 | Oct 16, 2014 |
| Oracle_linux | — | Upgrade tigervnc-serverUpgrade tigervnc-licenseUpgrade tigervncUpgrade tigervnc-server-minimalUpgrade tigervnc-server-appletUpgrade tigervnc-server-moduleUpgrade tigervnc-icons | Oct 16, 2024 | Oct 16, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 10, 2014 |
| Suse | — | Upgrade libXvnc1Upgrade tigervncUpgrade libXvnc-develUpgrade xorg-x11-Xvnc-novncUpgrade xorg-x11-Xvnc-moduleUpgrade xorg-x11-Xvnc | Dec 18, 2015 | Oct 16, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub