Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:1841-1

Опубликовано: 05 нояб. 2020
Источник: suse-cvrf

Описание

Security update for tigervnc

This update for tigervnc fixes the following issues:

  • CVE-2020-26117: Server certificates were stored as certiticate authorities, allowing malicious owners of these certificates to impersonate any server after a client had added an exception (bsc#1176733)

This update was imported from the SUSE:SLE-15-SP1:Update update project.

Список пакетов

openSUSE Leap 15.1
libXvnc-devel-1.9.0-lp151.4.9.1
libXvnc1-1.9.0-lp151.4.9.1
tigervnc-1.9.0-lp151.4.9.1
tigervnc-x11vnc-1.9.0-lp151.4.9.1
xorg-x11-Xvnc-1.9.0-lp151.4.9.1
xorg-x11-Xvnc-java-1.9.0-lp151.4.9.1
xorg-x11-Xvnc-module-1.9.0-lp151.4.9.1
xorg-x11-Xvnc-novnc-1.9.0-lp151.4.9.1

Описание

In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.


Затронутые продукты
openSUSE Leap 15.1:libXvnc-devel-1.9.0-lp151.4.9.1
openSUSE Leap 15.1:libXvnc1-1.9.0-lp151.4.9.1
openSUSE Leap 15.1:tigervnc-1.9.0-lp151.4.9.1
openSUSE Leap 15.1:tigervnc-x11vnc-1.9.0-lp151.4.9.1

Ссылки