CVE-2017-7394Improper Input Validation in Tigervnc

Severity
7.5HIGHNVD
EPSS
2.8%
top 13.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 1
Latest updateMay 14

Description

In TigerVNC 1.7.1 (SSecurityPlain.cxx SSecurityPlain::processMsg), unauthenticated users can crash the server by sending long usernames.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/tigervnc< tigervnc 1.7.0+dfsg-7 (bookworm)
Debiantigervnc/tigervnc< 1.7.0+dfsg-7+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p2f4-v5gm-9wqj: In TigerVNC 12022-05-14
OSV
CVE-2017-7394: In TigerVNC 12017-04-01

📋Vendor Advisories

2
Red Hat
tigervnc: Server crash via long usernames2017-03-29
Debian
CVE-2017-7394: tigervnc - In TigerVNC 1.7.1 (SSecurityPlain.cxx SSecurityPlain::processMsg), unauthenticat...2017

💬Community

2
Bugzilla
CVE-2017-7392 CVE-2017-7393 CVE-2017-7394 CVE-2017-7395 CVE-2017-7396 tigervnc: various flaws [fedora-all]2017-04-04
Bugzilla
CVE-2017-7394 tigervnc: Server crash via long usernames2017-04-04
CVE-2017-7394 — Improper Input Validation in Tigervnc | cvebase