TightVNC Repeated Challenge Replay Attack Vulnerability
BID:5296
Info
TightVNC Repeated Challenge Replay Attack Vulnerability
| Bugtraq ID: | 5296 |
| Class: | Design Error |
| CVE: |
CVE-2002-1336 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Discovered by [email protected]. |
| Vulnerable: |
TightVNC TightVNC 1.2.5 TightVNC TightVNC 1.2.4 TightVNC TightVNC 1.2.3 TightVNC TightVNC 1.2.2 TightVNC TightVNC 1.2.1 TightVNC TightVNC 1.2 .0 Avaya Labs Libsafe 1.2.2 AT&T VNC 3.3.6 AT&T VNC 3.3.5 AT&T VNC 3.3.4 AT&T VNC 3.3.3 R2 AT&T VNC 3.3.3 |
| Not Vulnerable: |
TightVNC TightVNC 1.2.6 |
Discussion
TightVNC Repeated Challenge Replay Attack Vulnerability
TightVNC is a Virtual Network Computing (VNC) client and server, available for a number of platforms including Microsoft Windows and Linux.
TightVNC, has been reported to repeat DES challenges if multiple connections are initiated in rapid sequence. A network eavesdropper may repeat a previously witnessed response, and authenticate as a valid user.
This behavior has been reported in version 1.2.1 of TightVNC for Unix. Other versions may share this vulnerability, this has not however been confirmed.
TightVNC is a Virtual Network Computing (VNC) client and server, available for a number of platforms including Microsoft Windows and Linux.
TightVNC, has been reported to repeat DES challenges if multiple connections are initiated in rapid sequence. A network eavesdropper may repeat a previously witnessed response, and authenticate as a valid user.
This behavior has been reported in version 1.2.1 of TightVNC for Unix. Other versions may share this vulnerability, this has not however been confirmed.
Exploit / POC
TightVNC Repeated Challenge Replay Attack Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
TightVNC Repeated Challenge Replay Attack Vulnerability
Solution:
Sun have released a security alert (Sun Alert ID:56161) to acknowledge this issue in Sun Linux 5. A workaround has been described in the workaround section of this BID to address this issue. Fixes are pending release. See referenced alert for further details.
Sun have made fixes available to address this issue in Sun Linux 5.0.7. Fixes are linked below.
Gentoo Linux has released an advisory. Users who have installed net-misc/vnc or net-misc/tightvnc are advised to upgrade by issuing the following commands:
emerge sync
emerge -u tightvnc
emerge clean
or
emerge sync
emerge -u vnc
emerge clean
Conectiva has released advisory CLA-2003:640 with fixes to address this issue. Security advisory CLSA-2003:670 has also been released containing a fix for CLEE 1.0, users are advised to upgrade as soon as possible.
TightVNC TightVNC 1.2 .0
TightVNC TightVNC 1.2.1
Avaya Labs Libsafe 1.2.2
TightVNC TightVNC 1.2.2
TightVNC TightVNC 1.2.3
TightVNC TightVNC 1.2.4
TightVNC TightVNC 1.2.5
AT&T VNC 3.3.3
AT&T VNC 3.3.3 R2
Solution:
Sun have released a security alert (Sun Alert ID:56161) to acknowledge this issue in Sun Linux 5. A workaround has been described in the workaround section of this BID to address this issue. Fixes are pending release. See referenced alert for further details.
Sun have made fixes available to address this issue in Sun Linux 5.0.7. Fixes are linked below.
Gentoo Linux has released an advisory. Users who have installed net-misc/vnc or net-misc/tightvnc are advised to upgrade by issuing the following commands:
emerge sync
emerge -u tightvnc
emerge clean
or
emerge sync
emerge -u vnc
emerge clean
Conectiva has released advisory CLA-2003:640 with fixes to address this issue. Security advisory CLSA-2003:670 has also been released containing a fix for CLEE 1.0, users are advised to upgrade as soon as possible.
TightVNC TightVNC 1.2 .0
-
TightVNC TightVNC 1.2.6
http://www.tightvnc.com/download.html
TightVNC TightVNC 1.2.1
-
TightVNC TightVNC 1.2.6
http://www.tightvnc.com/download.html
Avaya Labs Libsafe 1.2.2
-
TightVNC TightVNC 1.2.6
http://www.tightvnc.com/download.html
TightVNC TightVNC 1.2.2
-
Red Hat vnc-3.3.3r2-18.6.i386.rpm
Red Hat Linux 7.0
ftp://updates.redhat.com/7.0/en/os/i386/vnc-3.3.3r2-18.6.i386.rpm -
Red Hat vnc-3.3.3r2-18.6.i386.rpm
Red Hat Linux 7.1
ftp://updates.redhat.com/7.1/en/os/i386/vnc-3.3.3r2-18.6.i386.rpm -
Red Hat vnc-3.3.3r2-18.6.i386.rpm
Red Hat Linux 7.2
ftp://updates.redhat.com/7.2/en/os/i386/vnc-3.3.3r2-18.6.i386.rpm -
Red Hat vnc-3.3.3r2-18.6.src.rpm
Red Hat Linux 7.0
ftp://updates.redhat.com/7.0/en/os/SRPMS/vnc-3.3.3r2-18.6.src.rpm -
Red Hat vnc-3.3.3r2-18.6.src.rpm
Red Hat Linux 7.1
ftp://updates.redhat.com/7.1/en/os/SRPMS/vnc-3.3.3r2-18.6.src.rpm -
Red Hat vnc-3.3.3r2-18.6.src.rpm
Red Hat Linux 7.2
ftp://updates.redhat.com/7.2/en/os/SRPMS/vnc-3.3.3r2-18.6.src.rpm -
Red Hat vnc-3.3.3r2-28.2.i386.rpm
Red Hat Linux 7.3
ftp://updates.redhat.com/7.3/en/os/i386/vnc-3.3.3r2-28.2.i386.rpm -
Red Hat vnc-3.3.3r2-28.2.src.rpm
Red Hat Linux 7.3
ftp://updates.redhat.com/7.3/en/os/SRPMS/vnc-3.3.3r2-28.2.src.rpm -
Red Hat vnc-3.3.3r2-39.2.i386.rpm
Red Hat Linux 8.0
ftp://updates.redhat.com/8.0/en/os/i386/vnc-3.3.3r2-39.2.i386.rpm -
Red Hat vnc-3.3.3r2-39.2.src.rpm
Red Hat Linux 8.0
ftp://updates.redhat.com/8.0/en/os/SRPMS/vnc-3.3.3r2-39.2.src.rpm -
Red Hat vnc-doc-3.3.3r2-18.6.i386.rpm
Red Hat Linux 7.0
ftp://updates.redhat.com/7.0/en/os/i386/vnc-doc-3.3.3r2-18.6.i386.rpm -
Red Hat vnc-doc-3.3.3r2-18.6.i386.rpm
Red Hat Linux 7.1
ftp://updates.redhat.com/7.1/en/os/i386/vnc-doc-3.3.3r2-18.6.i386.rpm -
Red Hat vnc-doc-3.3.3r2-18.6.i386.rpm
Red Hat Linux 7.2
ftp://updates.redhat.com/7.2/en/os/i386/vnc-doc-3.3.3r2-18.6.i386.rpm -
Red Hat vnc-doc-3.3.3r2-28.2.i386.rpm
Red Hat Linux 7.3
ftp://updates.redhat.com/7.3/en/os/i386/vnc-doc-3.3.3r2-28.2.i386.rpm -
Red Hat vnc-doc-3.3.3r2-39.2.i386.rpm
Red Hat Linux 8.0
ftp://updates.redhat.com/8.0/en/os/i386/vnc-doc-3.3.3r2-39.2.i386.rpm -
Red Hat vnc-server-3.3.3r2-18.6.i386.rpm
Red Hat Linux 7.0
ftp://updates.redhat.com/7.0/en/os/i386/vnc-server-3.3.3r2-18.6.i386.r pm -
Red Hat vnc-server-3.3.3r2-18.6.i386.rpm
Red Hat Linux 7.1
ftp://updates.redhat.com/7.1/en/os/i386/vnc-server-3.3.3r2-18.6.i386.r pm -
Red Hat vnc-server-3.3.3r2-18.6.i386.rpm
Red Hat Linux 7.2
ftp://updates.redhat.com/7.2/en/os/i386/vnc-server-3.3.3r2-18.6.i386.r pm -
Red Hat vnc-server-3.3.3r2-28.2.i386.rpm
Red Hat Linux 7.3
ftp://updates.redhat.com/7.3/en/os/i386/vnc-server-3.3.3r2-28.2.i386.r pm -
Red Hat vnc-server-3.3.3r2-39.2.i386.rpm
Red Hat Linux 8.0
ftp://updates.redhat.com/8.0/en/os/i386/vnc-server-3.3.3r2-39.2.i386.r pm
TightVNC TightVNC 1.2.3
-
TightVNC TightVNC 1.2.6
http://www.tightvnc.com/download.html
TightVNC TightVNC 1.2.4
-
TightVNC TightVNC 1.2.6
http://www.tightvnc.com/download.html
TightVNC TightVNC 1.2.5
-
MandrakeSoft tightvnc-1.2.5-2.3mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft tightvnc-doc-1.2.5-2.3mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft tightvnc-server-1.2.5-2.3mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
TightVNC TightVNC 1.2.6
http://www.tightvnc.com/download.html
AT&T VNC 3.3.3
-
Conectiva vnc-3.3.3-6U70_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/vnc-3.3.3-6U70_2cl.i386.r pm -
Conectiva vnc-3.3.3r2+tight1.2.2-6U80_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/vnc-3.3.3r2+tight1.2.2-6U80 _1cl.i386.rpm -
Conectiva vnc-java-3.3.3r2+tight1.2.2-6U80_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/vnc-java-3.3.3r2+tight1.2.2 -6U80_1cl.i386.rpm -
Conectiva vnc-server-3.3.3r2+tight1.2.2-6U80_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/vnc-server-3.3.3r2+tight1.2 .2-6U80_1cl.i386.rpm -
MandrakeSoft vnc-3.3.3-8.4mdk.i586.rpm
Linux-Mandrake 7.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-doc-3.3.3-8.4mdk.i586.rpm
Linux-Mandrake 7.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-java-3.3.3-8.4mdk.i586.rpm
Linux-Mandrake 7.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-server-3.3.3-8.4mdk.i586.rpm
Linux-Mandrake 7.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-SVGALIB-3.3.3-8.4mdk.i586.rpm
Linux-Mandrake 7.2
http://www.mandrakesecure.net/en/ftp.php
AT&T VNC 3.3.3 R2
-
MandrakeSoft vnc-3.3.3r2-9.3mdk.i586.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-3.3.3r2-9.3mdk.i586.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-3.3.3r2-9.3mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-3.3.3r2-9.3mdk.ppc.rpm
Mandrake Linux 8.0/PPC
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-3.3.3r2-9.3mdk.ppc.rpm
Mandrake Linux 8.2/PPC
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-doc-3.3.3r2-9.3mdk.i586.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-doc-3.3.3r2-9.3mdk.i586.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-doc-3.3.3r2-9.3mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-doc-3.3.3r2-9.3mdk.ppc.rpm
Mandrake Linux 8.0/PPC
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-doc-3.3.3r2-9.3mdk.ppc.rpm
Mandrake Linux 8.2/PPC
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-server-3.3.3r2-9.3mdk.i586.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-server-3.3.3r2-9.3mdk.i586.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-server-3.3.3r2-9.3mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-server-3.3.3r2-9.3mdk.ppc.rpm
Mandrake Linux 8.0/PPC
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft vnc-server-3.3.3r2-9.3mdk.ppc.rpm
Mandrake Linux 8.2/PPC
http://www.mandrakesecure.net/en/ftp.php
References
TightVNC Repeated Challenge Replay Attack Vulnerability
References:
References:
- CLSA-2003:670 (Conectiva)
- Sun Alert ID: 56161 (Sun)
- Sun Linux Support - Sun Linux Patches (Sun)
- TightVNC Changelog (TightVNC)
- TightVNC Homepage (TightVNC)