Описание
Security update for tigervnc
This update for tigervnc fixes the following issues:
- CVE-2026-34352: Fixed permissions to prevent other users from observing the screen, or modifying what is sent to the client. (bsc#1260871)
Список пакетов
Image SLES12-SP5-Azure-SAP-BYOS
libXvnc1-1.6.0-22.23.1
xorg-x11-Xvnc-1.6.0-22.23.1
Image SLES12-SP5-Azure-SAP-On-Demand
libXvnc1-1.6.0-22.23.1
xorg-x11-Xvnc-1.6.0-22.23.1
Image SLES12-SP5-EC2-SAP-BYOS
libXvnc1-1.6.0-22.23.1
xorg-x11-Xvnc-1.6.0-22.23.1
Image SLES12-SP5-EC2-SAP-On-Demand
libXvnc1-1.6.0-22.23.1
xorg-x11-Xvnc-1.6.0-22.23.1
Image SLES12-SP5-GCE-SAP-BYOS
libXvnc1-1.6.0-22.23.1
xorg-x11-Xvnc-1.6.0-22.23.1
Image SLES12-SP5-GCE-SAP-On-Demand
libXvnc1-1.6.0-22.23.1
xorg-x11-Xvnc-1.6.0-22.23.1
SUSE Linux Enterprise Server 12 SP5-LTSS
libXvnc1-1.6.0-22.23.1
tigervnc-1.6.0-22.23.1
xorg-x11-Xvnc-1.6.0-22.23.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
libXvnc1-1.6.0-22.23.1
tigervnc-1.6.0-22.23.1
xorg-x11-Xvnc-1.6.0-22.23.1
Ссылки
- Link for SUSE-SU-2026:1301-1
- E-Mail link for SUSE-SU-2026:1301-1
- SUSE Security Ratings
- SUSE Bug 1260871
- SUSE CVE CVE-2026-34352 page
Описание
In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.
Затронутые продукты
Image SLES12-SP5-Azure-SAP-BYOS:libXvnc1-1.6.0-22.23.1
Image SLES12-SP5-Azure-SAP-BYOS:xorg-x11-Xvnc-1.6.0-22.23.1
Image SLES12-SP5-Azure-SAP-On-Demand:libXvnc1-1.6.0-22.23.1
Image SLES12-SP5-Azure-SAP-On-Demand:xorg-x11-Xvnc-1.6.0-22.23.1
Ссылки
- CVE-2026-34352
- SUSE Bug 1260871