Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TigerVNC证书验证安全绕过漏洞
Vulnerability Description
TigerVNC 1.1beta1版本的vncviewer组件中存在安全绕过漏洞,由于common/rfb/CSecurityTLS.cxx中的CSecurityTLS::processMsg函数不能正确验证服务器X.509证书。中间人攻击者可以借助任意证书欺骗TLS VNC服务器。
CVSS Information
N/A
Vulnerability Type
N/A