The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.
{
"binaries": [
{
"binary_name": "tigervnc-common",
"binary_version": "1.7.0+dfsg-8ubuntu2"
},
{
"binary_name": "tigervnc-common-dbgsym",
"binary_version": "1.7.0+dfsg-8ubuntu2"
},
{
"binary_name": "tigervnc-scraping-server",
"binary_version": "1.7.0+dfsg-8ubuntu2"
},
{
"binary_name": "tigervnc-scraping-server-dbgsym",
"binary_version": "1.7.0+dfsg-8ubuntu2"
},
{
"binary_name": "tigervnc-standalone-server",
"binary_version": "1.7.0+dfsg-8ubuntu2"
},
{
"binary_name": "tigervnc-standalone-server-dbgsym",
"binary_version": "1.7.0+dfsg-8ubuntu2"
},
{
"binary_name": "tigervnc-viewer",
"binary_version": "1.7.0+dfsg-8ubuntu2"
},
{
"binary_name": "tigervnc-viewer-dbgsym",
"binary_version": "1.7.0+dfsg-8ubuntu2"
},
{
"binary_name": "tigervnc-xorg-extension",
"binary_version": "1.7.0+dfsg-8ubuntu2"
},
{
"binary_name": "tigervnc-xorg-extension-dbgsym",
"binary_version": "1.7.0+dfsg-8ubuntu2"
}
],
"availability": "No subscription required"
}