A buffer overflow vulnerability in ModifiablePixelBuffer::fillRect in vncviewer was found allowing malicious VNC server to send crafted RRE message and possibly take control of the TigerVNC viewer. Upstream patch: https://github.com/TigerVNC/tigervnc/commit/18c020124ff1b2441f714da2017f63dba50720ba PR: https://github.com/TigerVNC/tigervnc/pull/399 Reference: http://seclists.org/oss-sec/2017/q1/166
Created tigervnc tracking bugs for this issue: Affects: fedora-all [bug 1415719]
This fix has been merged to tigervnc 1.7.1 which is already included in Fedora and pushed as regular update. Not sure whether I should change the update description and type or leave it as it is.
CVE assignment: http://seclists.org/oss-sec/2017/q1/189
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2017:0630 https://rhn.redhat.com/errata/RHSA-2017-0630.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:2000 https://access.redhat.com/errata/RHSA-2017:2000