Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g8f8-5m52-5p35

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.

EPSS

Процентиль: 67%
0.00561
Низкий

Дефекты

CWE-20

Связанные уязвимости

redhat
около 14 лет назад

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.

nvd
около 14 лет назад

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.

debian
около 14 лет назад

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx i ...

oracle-oval
около 14 лет назад

ELSA-2011-0871: tigervnc security update (MODERATE)

EPSS

Процентиль: 67%
0.00561
Низкий

Дефекты

CWE-20