Fedora Account System
Red Hat Associate
Red Hat Customer
The Xvnc server (tigervnc-server) and VNC extension for the Xorg server (tigervnc-server-module) are built with xorg-x11-server-source, but have not been rebuilt since the numerous security issues announced in December 2014 (CVE-2014-8091, CVE-2014-8092, CVE-2014-8093, CVE-2014-8094, CVE-2014-8095, CVE-2014-8096, CVE-2014-8097, CVE-2014-8098, CVE-2014-8099, CVE-2014-8100, CVE-2014-8101, CVE-2014-8102, CVE-2014-8103). Therefore, 1) tigervnc needs to be rebuilt for all supported branches in both Fedora and RHEL, and 2) something needs to be put in place that CVEs in xorg-x11-server also trigger notifications for tigervnc.
(In reply to Yaakov Selkowitz from comment #0) > 2) something needs to be put in place that CVEs in xorg-x11-server also > trigger notifications for tigervnc. X server issues do not get automatically handled as security for *vnc, as the X server there is not suid-root and hence no privilege escalation vector.
Closed wontfix as per thogers comment.