Pavel Cheremushkin from Kaspersky Lab various implementations of the VNC (Virtual Network Computing) remote access system and identified 37 vulnerabilities caused by memory management issues. The vulnerabilities found in VNC server implementations can only be exploited by authenticated users, while attacks on vulnerabilities in client code are possible when a user connects to a server controlled by an attacker.
The highest number of vulnerabilities was found in the , which is available only for the Windows platform. In total, 22 vulnerabilities were identified in UltraVNC. 13 vulnerabilities could potentially lead to code execution on the system, 5 to leakage of memory regions, and 4 to denial of service.
The vulnerabilities have been fixed in the release .
In the open library (LibVNCServer and LibVNCClient), which in VirtualBox, 10 vulnerabilities were discovered.
5 vulnerabilities (, , , , ) are caused by buffer overflows and can potentially lead to code execution. 3 vulnerabilities may lead to information leakage, and 2 to denial of service.
All issues have already been addressed by the developers, but changes are currently only in the master branch.
İ (the cross-platform deprecated branch was tested, as the current version 2.x is released only for Windows), 4 vulnerabilities were found. Three issues ( CVE-2019-15679, , CVE-2019-15680notified In the cross-platform package
TurboVNC CVE-2019-15683on August 23 Pavel Cheremushkin from Kaspersky Lab analyzed various implementations of the system. .
Mənbə: opennet.ru
