CVE-2014-8241
published 2016-12-14CVE-2014-8241: XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a…
PriorityP339critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.06%
86.1th percentile
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tigervnc | < tigervnc 1.7.0-2 (bookworm) | tigervnc 1.7.0-2 (bookworm) |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| tigervnc | tigervnc | >= 0 < 1.7.0-2 | 1.7.0-2 |
| tigervnc | tigervnc | >= 0 < 1.7.0-2 | 1.7.0-2 |
| tigervnc | tigervnc | >= 0 < 1.7.0-2 | 1.7.0-2 |
| tigervnc | tigervnc | >= 0 < 1.7.0-2 | 1.7.0-2 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tigervnc: NULL pointer dereference flaw in XRegion
vendor_redhat·2014-10-10·CVSS 7.5
CVE-2014-8241 [HIGH] CWE-476 tigervnc: NULL pointer dereference flaw in XRegion
tigervnc: NULL pointer dereference flaw in XRegion
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
A NULL pointer dereference flaw was found in TigerVNC's XRegion. A malicious VNC server could use this flaw to cause a client to crash.
Statement: This issue affects the version of tigervnc as shipped with Red Hat Enterprise Linux 5 and 6. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates of Red Hat Enterprise Linux 5 and 6.
Package: vnc (Red Hat Enterprise Linux 5) - Will not fix
Package: tigervnc (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2014-8241: tigervnc - XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL...
vendor_debian·2014·CVSS 7.5
CVE-2014-8241 [HIGH] CVE-2014-8241: tigervnc - XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL...
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
Scope: local
bookworm: resolved (fixed in 1.7.0-2)
bullseye: resolved (fixed in 1.7.0-2)
forky: resolved (fixed in 1.7.0-2)
sid: resolved (fixed in 1.7.0-2)
trixie: resolved (fixed in 1.7.0-2)
GHSA
GHSA-gq2g-qwmw-m5q3: XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return v
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2014-8241 [HIGH] CWE-476 GHSA-gq2g-qwmw-m5q3: XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return v
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
OSV
CVE-2014-8241: XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return v
osv·2016-12-14·CVSS 7.5
CVE-2014-8241 [HIGH] CVE-2014-8241: XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return v
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
No detection rules found.
No public exploits indexed.
http://seclists.org/oss-sec/2014/q4/278http://seclists.org/oss-sec/2014/q4/300http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70390https://bugzilla.redhat.com/show_bug.cgi?id=1151312https://rhn.redhat.com/errata/RHSA-2015-2233.htmlhttp://seclists.org/oss-sec/2014/q4/278http://seclists.org/oss-sec/2014/q4/300http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70390https://bugzilla.redhat.com/show_bug.cgi?id=1151312https://rhn.redhat.com/errata/RHSA-2015-2233.html
2016-12-14
Published