Description
In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2396-1 | tigervnc security update |
EUVD |
EUVD-2020-18747 | In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception. |
Ubuntu USN |
USN-5965-1 | TigerVNC vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T15:49:07.161Z
Reserved: 2020-09-27T00:00:00.000Z
Link: CVE-2020-26117
No data.
Status : Modified
Published: 2020-09-27T04:15:11.650
Modified: 2024-11-21T05:19:16.850
Link: CVE-2020-26117
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN