{"id":53107,"date":"2019-11-24T00:00:00","date_gmt":"2019-11-23T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/37-uyazvimostej-v-razlichnyh-realizatsiyah-vnc"},"modified":"2020-02-18T14:00:58","modified_gmt":"2020-02-18T11:00:58","slug":"37-uyazvimostej-v-razlichnyh-realizatsiyah-vnc","status":"publish","type":"post","link":"https:\/\/prohoster.info\/az\/blog\/news\/37-uyazvimostej-v-razlichnyh-realizatsiyah-vnc","title":{"rendered":"VNC-nin m\u00fcxt\u0259lif realla\u015fd\u0131rmalar\u0131nda 37 t\u0259hl\u00fck\u0259sizlik a\u00e7\u0131\u011f\u0131","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Pavel Cheremushkin from Kaspersky Lab <noindex><a rel=\"nofollow\" href=\"https:\/\/ics-cert.kaspersky.ru\/reports\/2019\/11\/13\/vnc-vulnerability-research\/\">analyzed<\/a><\/noindex> various implementations of the VNC (Virtual Network Computing) remote access system and identified 37 vulnerabilities caused by memory management issues. The vulnerabilities found in VNC server implementations can only be exploited by authenticated users, while attacks on vulnerabilities in client code are possible when a user connects to a server controlled by an attacker.<\/p>\n<p>The highest number of vulnerabilities was found in the <noindex><a rel=\"nofollow\" href=\"https:\/\/www.uvnc.com\/\">UltraVNC<\/a><\/noindex>, which is available only for the Windows platform. In total, 22 vulnerabilities were identified in UltraVNC. 13 vulnerabilities could potentially lead to code execution on the system, 5 to leakage of memory regions, and 4 to denial of service.<br \/>\nThe vulnerabilities have been fixed in the release <noindex><a rel=\"nofollow\" href=\"https:\/\/www.uvnc.com\/downloads\/ultravnc.html\">1.2.3.0<\/a><\/noindex>.<\/p>\n<p>In the open library <noindex><a rel=\"nofollow\" href=\"http:\/\/libvnc.github.io\/\">LibVNC<\/a><\/noindex> (LibVNCServer and LibVNCClient), which <noindex><a rel=\"nofollow\" href=\"http:\/\/libvnc.github.io\/success.html\">istifad\u0259 olunur<\/a><\/noindex> in VirtualBox, 10 vulnerabilities were discovered.<br \/>\n5 vulnerabilities (<noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-20020\">CVE-2018-20020<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-20019\">CVE-2018-20019<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-15127\">CVE-2018-15127<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-15126\">CVE-2018-15126<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6307\">CVE-2018-6307<\/a><\/noindex>) are caused by buffer overflows and can potentially lead to code execution. 3 vulnerabilities may lead to information leakage, and 2 to denial of service.<br \/>\nAll issues have already been addressed by the developers, but changes are currently <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/LibVNC\/libvncserver\/commit\/6073771eed1caf72f196e410182471e0dfd32149\">reflected<\/a><\/noindex> only in the master branch.<\/p>\n<p>\u0130  <noindex><a rel=\"nofollow\" href=\"https:\/\/sourceforge.net\/projects\/vnc-tight\/\">TightVNC<\/a><\/noindex> (the cross-platform deprecated branch was tested, as the current version 2.x is released only for Windows), 4 vulnerabilities were found. Three issues ( <noindex><a rel=\"nofollow\" href=\"https:\/\/www.tightvnc.com\/download-old.php\">1.3<\/a><\/noindex>CVE-2019-15679<noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2019-15679\">CVE-2019-15678<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2019-15678\">CVE-2019-8287<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-8287\">) are caused by buffer overflows in the InitialiseRFBConnection, rfbServerCutText, and HandleCoRREBBP functions, potentially leading to code execution. One issue (<\/a><\/noindex>CVE-2019-15680<noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2019-15680\">) leads to denial of service. Although the TightVNC developers were<\/a><\/noindex>notified <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2018\/12\/10\/5\">of the issues last year, the vulnerabilities remain unpatched.<\/a><\/noindex> In the cross-platform package<\/p>\n<p>TurboVNC <noindex><a rel=\"nofollow\" href=\"https:\/\/www.turbovnc.org\/\">(a fork of TightVNC 1.3 using the libjpeg-turbo library), only one vulnerability (<\/a><\/noindex> CVE-2019-15683<noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2019-15683\">) was found, but it is critical, and with authenticated access to the server, it allows for code execution as the buffer overflow enables controlling the return address. The issue was fixed<\/a><\/noindex>on August 23 <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/TurboVNC\/turbovnc\/commit\/cea98166008301e614e0d36776bf9435a536136e\">and does not appear in the current release.<\/a><\/noindex> Pavel Cheremushkin from Kaspersky Lab analyzed various implementations of the system. <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/TurboVNC\/turbovnc\/releases\">2.2.3<\/a><\/noindex>.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>M\u0259nb\u0259: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51922\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0430\u0432\u0435\u043b \u0427\u0435\u0440\u0435\u043c\u0443\u0448\u043a\u0438\u043d \u0438\u0437 \u041b\u0430\u0431\u043e\u0440\u0430\u0442\u043e\u0440\u0438\u0438 \u041a\u0430\u0441\u043f\u0435\u0440\u0441\u043a\u043e\u0433\u043e \u043f\u0440\u043e\u0430\u043d\u0430\u043b\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043b \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0434\u043e\u0441\u0442\u0443\u043f\u0430 VNC (Virtual Network Computing) \u0438 \u0432\u044b\u044f\u0432\u0438\u043b 37 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0432\u044b\u0437\u0432\u0430\u043d\u043d\u044b\u0445 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u043c\u0438 \u043f\u0440\u0438 \u0440\u0430\u0431\u043e\u0442\u0435 \u0441 \u043f\u0430\u043c\u044f\u0442\u044c\u044e. \u0412\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0435 \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f\u0445 VNC-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u0442\u043e\u043b\u044c\u043a\u043e \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c, \u0430 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u043c \u043a\u043e\u0434\u0435 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u044b \u043f\u0440\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u043a \u0441\u0435\u0440\u0432\u0435\u0440\u0443, \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u0443\u0435\u043c\u043e\u043c\u0443 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u043e\u043c. \u041d\u0430\u0438\u0431\u043e\u043b\u044c\u0448\u0435\u0435 \u0447\u0438\u0441\u043b\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-53107","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0430\u0432\u0435\u043b \u0427\u0435\u0440\u0435\u043c\u0443\u0448\u043a\u0438\u043d \u0438\u0437 \u041b\u0430\u0431\u043e\u0440\u0430\u0442\u043e\u0440\u0438\u0438 \u041a\u0430\u0441\u043f\u0435\u0440\u0441\u043a\u043e\u0433\u043e \u043f\u0440\u043e\u0430\u043d\u0430\u043b\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043b \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u044b.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/az\/blog\/news\/37-uyazvimostej-v-razlichnyh-realizatsiyah-vnc\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"az_AZ\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd4737 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f\u0445 VNC | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0430\u0432\u0435\u043b \u0427\u0435\u0440\u0435\u043c\u0443\u0448\u043a\u0438\u043d \u0438\u0437 \u041b\u0430\u0431\u043e\u0440\u0430\u0442\u043e\u0440\u0438\u0438 \u041a\u0430\u0441\u043f\u0435\u0440\u0441\u043a\u043e\u0433\u043e \u043f\u0440\u043e\u0430\u043d\u0430\u043b\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043b \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u044b.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/az\/blog\/news\/37-uyazvimostej-v-razlichnyh-realizatsiyah-vnc\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-23T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:00:58+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd4737 vulnerabilities in various VNC implementations | ProHoster","description":"Pavel Cheremushkin from Kaspersky Lab analyzed various implementations of the system.","canonical_url":"https:\/\/prohoster.info\/az\/blog\/news\/37-uyazvimostej-v-razlichnyh-realizatsiyah-vnc","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"az_AZ","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd4737 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f\u0445 VNC | ProHoster","og:description":"\u041f\u0430\u0432\u0435\u043b \u0427\u0435\u0440\u0435\u043c\u0443\u0448\u043a\u0438\u043d \u0438\u0437 \u041b\u0430\u0431\u043e\u0440\u0430\u0442\u043e\u0440\u0438\u0438 \u041a\u0430\u0441\u043f\u0435\u0440\u0441\u043a\u043e\u0433\u043e \u043f\u0440\u043e\u0430\u043d\u0430\u043b\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043b \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u044b.","og:url":"https:\/\/prohoster.info\/az\/blog\/news\/37-uyazvimostej-v-razlichnyh-realizatsiyah-vnc","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-23T21:00:00+00:00","article:modified_time":"2020-02-18T11:00:58+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"53107","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 06:07:23","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:31:28","updated":"2026-01-24 06:07:23","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/az\/wp-json\/wp\/v2\/posts\/53107","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/az\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/az\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/az\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/az\/wp-json\/wp\/v2\/comments?post=53107"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/az\/wp-json\/wp\/v2\/posts\/53107\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/az\/wp-json\/wp\/v2\/media?parent=53107"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/az\/wp-json\/wp\/v2\/categories?post=53107"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/az\/wp-json\/wp\/v2\/tags?post=53107"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}