CVE-2016-10207
published 2017-02-28CVE-2016-10207: The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.
PriorityP336high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.18%
86.6th percentile
The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tigervnc | < tigervnc 1.7.0-1 (bookworm) | tigervnc 1.7.0-1 (bookworm) |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| tigervnc | tigervnc | — | — |
| tigervnc | tigervnc | — | — |
| tigervnc | tigervnc | — | — |
| tigervnc | tigervnc | — | — |
| tigervnc | tigervnc | — | — |
| tigervnc | tigervnc | — | — |
| tigervnc | tigervnc | — | — |
| tigervnc | tigervnc | — | — |
| tigervnc | tigervnc | >= 0 < 1.7.0-1 | 1.7.0-1 |
| tigervnc | tigervnc | >= 0 < 1.7.0-1 | 1.7.0-1 |
| tigervnc | tigervnc | >= 0 < 1.7.0-1 | 1.7.0-1 |
| tigervnc | tigervnc | >= 0 < 1.7.0-1 | 1.7.0-1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tigervnc: VNC server can crash when TLS handshake terminates early
vendor_redhat·2016-08-23·CVSS 7.5
CVE-2016-10207 [HIGH] tigervnc: VNC server can crash when TLS handshake terminates early
tigervnc: VNC server can crash when TLS handshake terminates early
The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.
A denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early.
Debian
CVE-2016-10207: tigervnc - The Xvnc server in TigerVNC allows remote attackers to cause a denial of service...
vendor_debian·2016·CVSS 7.5
CVE-2016-10207 [HIGH] CVE-2016-10207: tigervnc - The Xvnc server in TigerVNC allows remote attackers to cause a denial of service...
The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.
Scope: local
bookworm: resolved (fixed in 1.7.0-1)
bullseye: resolved (fixed in 1.7.0-1)
forky: resolved (fixed in 1.7.0-1)
sid: resolved (fixed in 1.7.0-1)
trixie: resolved (fixed in 1.7.0-1)
GHSA
GHSA-xv2c-qf7g-w8gj: The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake earl
ghsa_unreviewed·2022-05-14
CVE-2016-10207 [HIGH] CWE-119 GHSA-xv2c-qf7g-w8gj: The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake earl
The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.
OSV
CVE-2016-10207: The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake earl
osv·2017-02-28·CVSS 7.5
CVE-2016-10207 [HIGH] CVE-2016-10207: The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake earl
The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-10207 tigervnc: VNC server can crash when TLS handshake terminates early
bugzilla·2017-02-02·CVSS 7.5
CVE-2016-10207 [HIGH] CVE-2016-10207 tigervnc: VNC server can crash when TLS handshake terminates early
CVE-2016-10207 tigervnc: VNC server can crash when TLS handshake terminates early
A vulnerability was found in tigerVNC. The Xvnc server from tigervnc can crash when a client terminates a TLS connection early. This is due to invalid initialization/deinitialization order of the GnuTLS library.
References:
http://seclists.org/oss-sec/2017/q1/297
Upstream patch:
https://github.com/TigerVNC/tigervnc/commit/8aa4bc53206c2430bbf0c8f4b642f59a379ee649
Discussion:
Created tigervnc tracking bugs for this issue:
Affects: fedora-all [bug 1415719]
---
CVE assignment:
http://seclists.org/oss-sec/2017/q1/312
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2017:0630 https://rhn.redhat.com/errata/RHSA-2017-0630.html
---
This issue has been ad
Bugzilla
CVE-2016-10207 CVE-2017-5581 tigervnc: various flaws [fedora-all]
bugzilla·2017-01-23·CVSS 7.5
CVE-2016-10207 [HIGH] CVE-2016-10207 CVE-2017-5581 tigervnc: various flaws [fedora-all]
CVE-2016-10207 CVE-2017-5581 tigervnc: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whil
http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00020.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0630.htmlhttp://www.openwall.com/lists/oss-security/2017/02/02/22http://www.openwall.com/lists/oss-security/2017/02/05/2http://www.securityfocus.com/bid/96012https://access.redhat.com/errata/RHSA-2017:2000https://bugzilla.suse.com/show_bug.cgi?id=1023012https://github.com/TigerVNC/tigervnc/commit/8aa4bc53206c2430bbf0c8f4b642f59a379ee649https://security.gentoo.org/glsa/201801-13http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00020.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0630.htmlhttp://www.openwall.com/lists/oss-security/2017/02/02/22http://www.openwall.com/lists/oss-security/2017/02/05/2http://www.securityfocus.com/bid/96012https://access.redhat.com/errata/RHSA-2017:2000https://bugzilla.suse.com/show_bug.cgi?id=1023012https://github.com/TigerVNC/tigervnc/commit/8aa4bc53206c2430bbf0c8f4b642f59a379ee649https://security.gentoo.org/glsa/201801-13
2017-02-28
Published