LibVNCServer Remote Authentication Bypass Vulnerability
BID:18977
CVE-2006-2450 |Info
LibVNCServer Remote Authentication Bypass Vulnerability
| Bugtraq ID: | 18977 |
| Class: | Design Error |
| CVE: |
CVE-2006-2450 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2006 12:00AM |
| Updated: | Mar 19 2007 06:04PM |
| Credit: | Ludovic Drolez <[email protected]> reported this vulnerability. |
| Vulnerable: |
S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 10.1 LibVNCServer VNC Library 0.7.1 LibVNCServer VNC Library 0.7 LibVNCServer VNC Library 0.6 LibVNCServer VNC Library 0.5 LibVNCServer VNC Library 0.4 LibVNCServer VNC Library 0.2 LibVNCServer VNC Library 0.1 beta Gentoo Linux |
| Not Vulnerable: | |
Discussion
LibVNCServer Remote Authentication Bypass Vulnerability
LibVNCServer is prone to an authentication-bypass vulnerability. This issue is due to a flaw in the authentication process of the affected package.
Exploiting this issue may allow attackers to gain unauthenticated, remote access to the VNC servers.
All versions of LibVNCServer are considered vulnerable to this issue.
Reports indicate that this issue is similar to the issue described in BID 17978 (RealVNC Remote Authentication Bypass Vulnerability). Note that since LibVNCServer and RealVNC do not share code, this issue is being assigned a separate BID.
LibVNCServer is prone to an authentication-bypass vulnerability. This issue is due to a flaw in the authentication process of the affected package.
Exploiting this issue may allow attackers to gain unauthenticated, remote access to the VNC servers.
All versions of LibVNCServer are considered vulnerable to this issue.
Reports indicate that this issue is similar to the issue described in BID 17978 (RealVNC Remote Authentication Bypass Vulnerability). Note that since LibVNCServer and RealVNC do not share code, this issue is being assigned a separate BID.
Exploit / POC
LibVNCServer Remote Authentication Bypass Vulnerability
To exploit this issue, attackers will likely modify readily available open-source VNC client software.
To exploit this issue, attackers will likely modify readily available open-source VNC client software.
Solution / Fix
LibVNCServer Remote Authentication Bypass Vulnerability
Solution:
The vendor has released an upstream fix to address this issue.
Please see the referenced advisories for more information.
S.u.S.E. Linux Professional 10.1
LibVNCServer VNC Library 0.1 beta
LibVNCServer VNC Library 0.2
LibVNCServer VNC Library 0.4
LibVNCServer VNC Library 0.5
LibVNCServer VNC Library 0.6
LibVNCServer VNC Library 0.7
LibVNCServer VNC Library 0.7.1
Solution:
The vendor has released an upstream fix to address this issue.
Please see the referenced advisories for more information.
S.u.S.E. Linux Professional 10.1
-
SuSE apparmor-admin_en-10-7.5.noarch.rpm
SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/noarch/apparmor-admin_en-1 0-7.5.noarch.rpm -
SuSE apparmor-docs-2.0-17.5.noarch.rpm
SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/noarch/apparmor-docs-2.0-1 7.5.noarch.rpm -
SuSE apparmor-profiles-2.0-34.9.noarch.rpm
SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/noarch/apparmor-profiles-2 .0-34.9.noarch.rpm -
SuSE apparmor-utils-2.0-23.5.noarch.rpm
SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/noarch/apparmor-utils-2.0- 23.5.noarch.rpm -
SuSE yast2-apparmor-2.0-27.5.noarch.rpm
SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/noarch/yast2-apparmor-2.0- 27.5.noarch.rpm
LibVNCServer VNC Library 0.1 beta
-
LibVNCServer Diff of /libvncserver/libvncserver/auth.c
http://libvncserver.cvs.sourceforge.net/libvncserver/libvncserver/libv ncserver/auth.c?r1=1.11&r2=1.14&diff_format=u
LibVNCServer VNC Library 0.2
-
LibVNCServer Diff of /libvncserver/libvncserver/auth.c
http://libvncserver.cvs.sourceforge.net/libvncserver/libvncserver/libv ncserver/auth.c?r1=1.11&r2=1.14&diff_format=u
LibVNCServer VNC Library 0.4
-
LibVNCServer Diff of /libvncserver/libvncserver/auth.c
http://libvncserver.cvs.sourceforge.net/libvncserver/libvncserver/libv ncserver/auth.c?r1=1.11&r2=1.14&diff_format=u
LibVNCServer VNC Library 0.5
-
LibVNCServer Diff of /libvncserver/libvncserver/auth.c
http://libvncserver.cvs.sourceforge.net/libvncserver/libvncserver/libv ncserver/auth.c?r1=1.11&r2=1.14&diff_format=u
LibVNCServer VNC Library 0.6
-
LibVNCServer Diff of /libvncserver/libvncserver/auth.c
http://libvncserver.cvs.sourceforge.net/libvncserver/libvncserver/libv ncserver/auth.c?r1=1.11&r2=1.14&diff_format=u
LibVNCServer VNC Library 0.7
-
LibVNCServer Diff of /libvncserver/libvncserver/auth.c
http://libvncserver.cvs.sourceforge.net/libvncserver/libvncserver/libv ncserver/auth.c?r1=1.11&r2=1.14&diff_format=u
LibVNCServer VNC Library 0.7.1
-
LibVNCServer Diff of /libvncserver/libvncserver/auth.c
http://libvncserver.cvs.sourceforge.net/libvncserver/libvncserver/libv ncserver/auth.c?r1=1.11&r2=1.14&diff_format=u
References
LibVNCServer Remote Authentication Bypass Vulnerability
References:
References:
- Debian Bug report logs - #376824 (Martin Pitt
) - LibVNCServer Project Home Page (LibVNCServer)