vnc4 authentication bypass
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
vnc4 (Debian) |
Fix Released
|
Unknown
|
|||
vnc4 (Ubuntu) |
Fix Released
|
Critical
|
Unassigned | ||
Dapper |
Fix Released
|
Critical
|
Unassigned | ||
Edgy |
Fix Released
|
Critical
|
Unassigned |
Bug Description
Binary package hint: vnc4server
Catalogued as Bug#395809: marked as done (vnc4 authentication bypass) in debian-bugs-rc
Apparently, this bug has been fixed in upstream versions of vnc4server (4.1.2), however the version in the Dapper repositories still contains the vulnerability.
dbott@thedrake:~$ sudo apt-cache show vnc4server
Package: vnc4server
Priority: optional
Section: universe/x11
Installed-Size: 2332
Maintainer: Ola Lundqvist <email address hidden>
Architecture: i386
Source: vnc4
Version: 4.1.1+xorg1.
Provides: vnc-server, x0vnc-server
Essentially, it allows the password to be bypassed in VNC server
(see my write-up here: http://
Links to references:
http://<email address hidden>
Some more information about this issue can be found in:
http://
http://
http://
http://
CVE References
Changed in vnc4: | |
importance: | Undecided → Critical |
Changed in vnc4: | |
status: | Unknown → Fix Released |
Changed in vnc4: | |
importance: | Undecided → Critical |
importance: | Undecided → Critical |
Changed in vnc4: | |
status: | Fix Committed → Fix Released |
Changed in vnc4: | |
status: | Fix Committed → Fix Released |
cve: http:// www.cve. mitre.org/ cgi-bin/ cvename. cgi?name= 2006-2369 bugs.debian. org/cgi- bin/bugreport. cgi?bug= 395809
debian: http://