VNC-nin müxtəlif reallaşdırmalarında 37 təhlükəsizlik açığı

Pavel Cheremushkin from Kaspersky Lab analyzed various implementations of the VNC (Virtual Network Computing) remote access system and identified 37 vulnerabilities caused by memory management issues. The vulnerabilities found in VNC server implementations can only be exploited by authenticated users, while attacks on vulnerabilities in client code are possible when a user connects to a server controlled by an attacker.

The highest number of vulnerabilities was found in the UltraVNC, which is available only for the Windows platform. In total, 22 vulnerabilities were identified in UltraVNC. 13 vulnerabilities could potentially lead to code execution on the system, 5 to leakage of memory regions, and 4 to denial of service.
The vulnerabilities have been fixed in the release 1.2.3.0.

In the open library LibVNC (LibVNCServer and LibVNCClient), which istifadə olunur in VirtualBox, 10 vulnerabilities were discovered.
5 vulnerabilities (CVE-2018-20020, CVE-2018-20019, CVE-2018-15127, CVE-2018-15126, CVE-2018-6307) are caused by buffer overflows and can potentially lead to code execution. 3 vulnerabilities may lead to information leakage, and 2 to denial of service.
All issues have already been addressed by the developers, but changes are currently reflected only in the master branch.

İ TightVNC (the cross-platform deprecated branch was tested, as the current version 2.x is released only for Windows), 4 vulnerabilities were found. Three issues ( 1.3CVE-2019-15679CVE-2019-15678, CVE-2019-8287, ) are caused by buffer overflows in the InitialiseRFBConnection, rfbServerCutText, and HandleCoRREBBP functions, potentially leading to code execution. One issue (CVE-2019-15680) leads to denial of service. Although the TightVNC developers werenotified of the issues last year, the vulnerabilities remain unpatched. In the cross-platform package

TurboVNC (a fork of TightVNC 1.3 using the libjpeg-turbo library), only one vulnerability ( CVE-2019-15683) was found, but it is critical, and with authenticated access to the server, it allows for code execution as the buffer overflow enables controlling the return address. The issue was fixedon August 23 and does not appear in the current release. Pavel Cheremushkin from Kaspersky Lab analyzed various implementations of the system. 2.2.3.

Mənbə: opennet.ru

DDoS qoruması olan saytlara etibarlı hosting satın alın, VPS VDS serverlər 🔥 DDoS qoruması olan saytlara etibarlı hosting satın alın, VPS VDS serverlər | ProHoster