[CLSA-2025:1744213437] tigervnc: Fix of 3 CVEs
Type:
security
Severity:
Critical
Release date:
2025-04-09 15:44:02 UTC
Description:
- CVE-2023-6816: xorg-x11-server: fix use-after-free issue by adding check to allocate sufficient space for logical button maps to prevent heap overflow in DeviceFocusEvent and XIQueryPointer replies - CVE-2023-5367: xorg-x11-server: correct buffer offset handling in XIChangeDeviceProperty and RRChangeOutputProperty to prevent out-of-bound writes during append/prepend operations - CVE-2023-6478: xorg-x11-server: fix integer overflow in RRChangeProviderProperty and RRChangeOutputProperty to prevent disclosure of sensitive information
Updated packages:
  • tigervnc-1.12.0-13.el9_2.tuxcare.els9.x86_64.rpm
    sha:eb7f45b1e95a0038d97f474bd52da0abcc6f6f81f897b7d19287b02ca84e6086
  • tigervnc-icons-1.12.0-13.el9_2.tuxcare.els9.noarch.rpm
    sha:f1832c0e99b9bec411568733151169113d66762cec9c435309a42828ec5b1d71
  • tigervnc-license-1.12.0-13.el9_2.tuxcare.els9.noarch.rpm
    sha:9c57fd269bad86ef4c47415dd12eae7dab2c280be1f844233b5f0150b0d171f7
  • tigervnc-selinux-1.12.0-13.el9_2.tuxcare.els9.noarch.rpm
    sha:e1d84b4b8803e9bf7ab956a66bdbca2e1d533fb0204c36ae89282db1f2be989e
  • tigervnc-server-1.12.0-13.el9_2.tuxcare.els9.x86_64.rpm
    sha:b6a11bb97b6ecd79b6b91a1363c73f2a70932c8a42267aeac602cffc5380a35e
  • tigervnc-server-minimal-1.12.0-13.el9_2.tuxcare.els9.x86_64.rpm
    sha:af20f857219423ea25a3e38039b6114d27e769250be904d7c039ee91494a0034
  • tigervnc-server-module-1.12.0-13.el9_2.tuxcare.els9.x86_64.rpm
    sha:0460a1fb2a28fd9325c5357c4efbbfdc47a535f9b2bf13f8d63595f2b672ad20
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.