In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution.
https://security.gentoo.org/glsa/201801-13
https://github.com/TigerVNC/tigervnc/pull/438