Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34352

Опубликовано: 26 мар. 2026
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.

A flaw was found in TigerVNC's x0vncserver component. Due to incorrect permissions in the Image.cxx file, other users on the system can observe or manipulate the screen contents of a running session. This vulnerability could also lead to an application crash, resulting in a Denial of Service (DoS).

Меры по смягчению последствий

The x0vncserver component should be disabled if not actively required. If x0vncserver is necessary, ensure that only trusted users have access to the system where it is running. To disable the x0vncserver service, if it is running as a systemd service, you can use: sudo systemctl stop x0vncserver.service sudo systemctl disable x0vncserver.service If x0vncserver is launched manually, avoid running it in multi-user environments. A service restart or system reboot may be required for changes to take full effect.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-279
https://bugzilla.redhat.com/show_bug.cgi?id=2452022TigerVNC: x0vncserver: TigerVNC x0vncserver: Information disclosure, data manipulation, and denial of service via incorrect permissions

EPSS

Процентиль: 16%
0.00247
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.5
ubuntu
4 месяца назад

In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.

CVSS3: 8.5
nvd
4 месяца назад

In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.

CVSS3: 8.5
debian
4 месяца назад

In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users ...

suse-cvrf
4 месяца назад

Security update for tigervnc

suse-cvrf
4 месяца назад

Security update for tigervnc

EPSS

Процентиль: 16%
0.00247
Низкий

6.3 Medium

CVSS3