Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2011-0871

Опубликовано: 15 июн. 2011
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2011-0871: tigervnc security update (MODERATE)

[1.0.90-0.15.20110314svn4359.1]

  • viewer can send password without proper validation of X.509 certs (CVE-2011-1775)

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

tigervnc

1.0.90-0.15.20110314svn4359.el6_1.1

tigervnc-server

1.0.90-0.15.20110314svn4359.el6_1.1

tigervnc-server-applet

1.0.90-0.15.20110314svn4359.el6_1.1

tigervnc-server-module

1.0.90-0.15.20110314svn4359.el6_1.1

Oracle Linux i686

tigervnc

1.0.90-0.15.20110314svn4359.el6_1.1

tigervnc-server

1.0.90-0.15.20110314svn4359.el6_1.1

tigervnc-server-applet

1.0.90-0.15.20110314svn4359.el6_1.1

tigervnc-server-module

1.0.90-0.15.20110314svn4359.el6_1.1

Связанные CVE

Связанные уязвимости

redhat
около 14 лет назад

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.

nvd
около 14 лет назад

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.

debian
около 14 лет назад

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx i ...

github
около 3 лет назад

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.