7.5
CVSSv2

CVE-2014-8241

Published: 14/12/2016 Updated: 20/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tigervnc tigervnc -

redhat enterprise linux server 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux desktop 7.0

redhat enterprise linux hpc node 7.0

Vendor Advisories

Synopsis Moderate: tigervnc security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated tigervnc packages that fix two security issues, several bugs, andadd various enhancements are now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this upd ...
Debian Bug report logs - #849478 tigervnc: CVE-2014-8241: NULL pointer dereference flaw in XRegion Package: src:tigervnc; Maintainer for src:tigervnc is TigerVNC Packaging Team <pkg-tigervnc-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 27 Dec 2016 16:09:02 UTC Sever ...
An integer overflow flaw, leading to a heap-based buffer overflow, was found in the way TigerVNC handled screen sizes A malicious VNC server could use this flaw to cause a client to crash or, potentially, execute arbitrary code on the client A NULL pointer dereference flaw was found in TigerVNC's XRegion A malicious VNC server could use this fla ...
A NULL pointer dereference flaw was found in TigerVNC's XRegion A malicious VNC server could use this flaw to cause a client to crash ...