In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Tigervnc | Tigervnc | * | 1.16.2 (excluding) |
| Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | RedHat | tigervnc-0:1.1.0-25.el6_10.16 | * |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | RedHat | tigervnc-0:1.8.0-36.el7_9.4 | * |
| Red Hat Enterprise Linux 8 | RedHat | tigervnc-0:1.15.0-9.el8_10 | * |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | tigervnc-0:1.11.0-8.el8_4.15 | * |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | RedHat | tigervnc-0:1.11.0-8.el8_4.15 | * |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | tigervnc-0:1.12.0-6.el8_6.17 | * |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | RedHat | tigervnc-0:1.12.0-6.el8_6.17 | * |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | RedHat | tigervnc-0:1.12.0-15.el8_8.17 | * |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | RedHat | tigervnc-0:1.12.0-15.el8_8.17 | * |
| Red Hat Enterprise Linux 9 | RedHat | tigervnc-0:1.15.0-6.el9_7.1 | * |
| Red Hat Enterprise Linux 9 | RedHat | tigervnc-0:1.15.0-7.el9_8.1 | * |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | RedHat | tigervnc-0:1.11.0-22.el9_0.17 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | tigervnc-0:1.12.0-14.el9_2.14 | * |
| Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | tigervnc-0:1.13.1-8.el9_4.9 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | tigervnc-0:1.14.1-10.el9_6 | * |
| Tigervnc | Ubuntu | questing | * |