Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-1775

Опубликовано: 04 мая 2011
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=702470tigervnc: vncviewer can send password to server without proper validation of the X.509 certificate

EPSS

Процентиль: 67%
0.00561
Низкий

2.6 Low

CVSS2

Связанные уязвимости

nvd
около 14 лет назад

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.

debian
около 14 лет назад

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx i ...

github
около 3 лет назад

The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.

oracle-oval
около 14 лет назад

ELSA-2011-0871: tigervnc security update (MODERATE)

EPSS

Процентиль: 67%
0.00561
Низкий

2.6 Low

CVSS2