Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-1775

Опубликовано: 26 мая 2011
Источник: nvd
CVSS2: 5.8
EPSS Низкий

Описание

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:tigervnc:tigervnc:1.1:beta1:*:*:*:*:*:*

EPSS

Процентиль: 67%
0.00561
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

redhat
больше 14 лет назад

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.

debian
около 14 лет назад

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx i ...

github
около 3 лет назад

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.

oracle-oval
около 14 лет назад

ELSA-2011-0871: tigervnc security update (MODERATE)

EPSS

Процентиль: 67%
0.00561
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-20