37 vulnerabilities in various implementations of VNC

Pavel Cheremushkin from Kaspersky Lab analyzed various implementations of the VNC (Virtual Network Computing) remote access system and identified 37 vulnerabilities caused by memory handling issues. The vulnerabilities found in VNC server implementations can only be exploited by authenticated users, while attacks on vulnerabilities in the client code are possible when a user connects to a server controlled by an attacker.

The highest number of vulnerabilities was found in the UltraVNC, available only for the Windows platform. A total of 22 vulnerabilities were identified in UltraVNC. 13 vulnerabilities can potentially lead to code execution in the system, 5 to leaking the contents of memory areas, and 4 to denial of service.
The vulnerabilities have been fixed in the release 1.2.3.0.

In the open library LibVNC (LibVNCServer and LibVNCClient), which a layer in VirtualBox, 10 vulnerabilities were identified.
5 vulnerabilities (CVE-2018-20020, CVE-2018-20019, CVE-2018-15127, CVE-2018-15126, CVE-2018-6307) are caused by buffer overflows and may potentially lead to code execution. 3 vulnerabilities can lead to information leakage, and 2 to denial of service.
All issues have already been resolved by the developers, but the changes are only reflected in the master branch.

In TightVNC (the cross-platform deprecated branch was tested, as the current version 2.x is released only for Windows), 4 vulnerabilities were found. Three issues ( 1.3CVE-2019-15679CVE-2019-15678, CVE-2019-8287, ) are caused by buffer overflows in the InitialiseRFBConnection, rfbServerCutText, and HandleCoRREBBP functions, and may potentially lead to code execution. One issue (CVE-2019-15680) leads to denial of service. Despite the fact that TightVNC developers wereaware of the issues last year, the vulnerabilities remain unpatched. informed In the cross-platform package

TurboVNC (a fork of TightVNC 1.3 that uses the libjpeg-turbo library), only one vulnerability was found ( CVE-2019-15683), but it is severe and, with authenticated access to the server, allows for remote code execution since the buffer overflow permits control over the return address. The issue was resolvedon August 23rd and does not appear in the current release. Pavel Cheremushkin from Kaspersky Lab analyzed various implementations of the system. 2.2.3.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster