In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution.
The product calls free() twice on the same memory address.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Tigervnc | Tigervnc | 1.7.1 (including) | 1.7.1 (including) |
| Red Hat Enterprise Linux 7 | RedHat | fltk-0:1.3.4-1.el7 | * |
| Red Hat Enterprise Linux 7 | RedHat | tigervnc-0:1.8.0-1.el7 | * |
| Tigervnc | Ubuntu | artful | * |
| Tigervnc | Ubuntu | upstream | * |
| Tigervnc | Ubuntu | zesty | * |