oss-sec mailing list archives

Re: CVE request: tigervnc


From: Josh Bressers <bressers () redhat com>
Date: Mon, 9 May 2011 14:52:03 -0400 (EDT)

----- Original Message -----
The vncviewer in tigervnc had X.509 certificate support added in svn
r4200 (currently beta, slated for the 1.1.0 release). It would prompt for
and send authentication credentials before properly validating the X.509
certificate, which makes it susceptible to a man-in-the-middle attack.

References:

https://bugzilla.redhat.com/show_bug.cgi?id=702470
http://www.mail-archive.com/tigervnc-devel () lists sourceforge net/msg01342.html
http://www.mail-archive.com/tigervnc-devel () lists sourceforge net/msg01347.html


Please use CVE-2011-1775.

Thanks.

-- 
    JB


Current thread: