INFSA-2024:9540: tigervnc security update

Information about definition

Identificator: INFSA-2024:9540

Type: security

Release date: 2024-12-13 13:16:23 UTC

Information about package

Virtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients.

Vulnerabilities description

  • CVE-2024-9632

    A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payload, leading to denial of service or local privilege escalation in distributions where the X.org server is run with root privileges.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
NIST — CVE-2024-9632
no information 7.8 no information
Critical, important, moderate, low

Updated packages