CVE-2014-8241

XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
Affected Products (NVD)
VendorProductVersion
tigervnctigervnc
-
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_hpc_node
7.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tigervnc
bookworm
1.12.0+dfsg-8
fixed
bullseye
1.11.0+dfsg-2+deb11u1
fixed
sid
1.13.1+dfsg-3
fixed
trixie
1.13.1+dfsg-3
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
tigervnc
RHEL 7
0:1.3.1-3.el7
fixed
tigervnc-icons
RHEL 7
0:1.3.1-3.el7
fixed
tigervnc-license
RHEL 7
0:1.3.1-3.el7
fixed
tigervnc-server
RHEL 7
0:1.3.1-3.el7
fixed
tigervnc-server-applet
RHEL 7
0:1.3.1-3.el7
fixed
tigervnc-server-minimal
RHEL 7
0:1.3.1-3.el7
fixed
tigervnc-server-module
RHEL 7
0:1.3.1-3.el7
fixed