XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade tigervnc | Jul 30, 2024 | Dec 14, 2016 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.3.0.0.30.0 on Solaris 11.3Upgrade consolidation/X/X-incorporation to version 0.5.11-0.175.3.0.0.30.1483 on Solaris 11.3 | May 29, 2017 | Dec 14, 2016 |
| Oracle_linux | — | Upgrade tigervnc-server-minimalUpgrade tigervnc-server-moduleUpgrade tigervnc-iconsUpgrade tigervnc-server-appletUpgrade tigervnc-serverUpgrade tigervnc-licenseUpgrade tigervnc | Oct 16, 2024 | Dec 14, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 10, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub