INFSA-2024:3067: tigervnc security update

Information about definition

Identificator: INFSA-2024:3067

Type: security

Release date: 2024-08-23 19:41:42 UTC

Information about package

Virtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients.

Vulnerabilities description

  • CVE-2023-5380

    A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
NIST — CVE-2023-5380
no information 4.7 no information
Critical, important, moderate, low

Updated packages