WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/2275 | vdb entry vendor advisory |
http://www.kb.cert.org/vuls/id/303080 | third party advisory us government resource |
https://exchange.xforce.ibmcloud.com/vulnerabilities/5992 | vdb entry |
http://www1.corest.com/common/showdoc.php?idxseccion=10&idx=117 | vendor advisory |