{"id":53107,"date":"2019-11-24T00:00:00","date_gmt":"2019-11-23T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/37-uyazvimostej-v-razlichnyh-realizatsiyah-vnc"},"modified":"2020-02-18T14:00:58","modified_gmt":"2020-02-18T11:00:58","slug":"37-uyazvimostej-v-razlichnyh-realizatsiyah-vnc","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/37-uyazvimostej-v-razlichnyh-realizatsiyah-vnc","title":{"rendered":"37 vulnerabilit\u0103\u021bi \u00een diverse implement\u0103ri VNC","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Pavel Cheremushkin de la Laboratorul Kaspersky <noindex><a rel=\"nofollow\" href=\"https:\/\/ics-cert.kaspersky.ru\/reports\/2019\/11\/13\/vnc-vulnerability-research\/\">a analizat<\/a><\/noindex> diverse implement\u0103ri ale sistemului de acces de la distan\u021b\u0103 VNC (Virtual Network Computing) \u0219i a identificat 37 de vulnerabilit\u0103\u021bi cauzate de probleme la gestionarea memoriei. Vulnerabilit\u0103\u021bile identificate \u00een implement\u0103rile serverelor VNC pot fi exploatate doar de utilizatori autentifica\u021bi, iar atacurile asupra vulnerabilit\u0103\u021bilor din codul clientului sunt posibile atunci c\u00e2nd utilizatorul se conecteaz\u0103 la un server controlat de un atacator.<\/p>\n<p>Cel mai mare num\u0103r de vulnerabilit\u0103\u021bi a fost g\u0103sit \u00een pachetul <noindex><a rel=\"nofollow\" href=\"https:\/\/www.uvnc.com\/\">UltraVNC<\/a><\/noindex>, disponibil doar pentru platforma Windows. \u00cen total, \u00een UltraVNC au fost identificate 22 de vulnerabilit\u0103\u021bi. 13 dintre ele pot conduce poten\u021bial la execu\u021bia de cod \u00een sistem, 5 la scurgeri de con\u021binut din zonele de memorie \u0219i 4 la refuzul de a presta servicii.<br \/>\nVulnerabilit\u0103\u021bile au fost remediate \u00een versiunea <noindex><a rel=\"nofollow\" href=\"https:\/\/www.uvnc.com\/downloads\/ultravnc.html\">1.2.3.0<\/a><\/noindex>.<\/p>\n<p>\u00cen biblioteca open-source <noindex><a rel=\"nofollow\" href=\"http:\/\/libvnc.github.io\/\">LibVNC<\/a><\/noindex> (LibVNCServer \u0219i LibVNCClient), care <noindex><a rel=\"nofollow\" href=\"http:\/\/libvnc.github.io\/success.html\">se folose\u0219te<\/a><\/noindex> \u00een VirtualBox, au fost g\u0103site 10 vulnerabilit\u0103\u021bi.<br \/>\n5 vulnerabilit\u0103\u021bi (<noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-20020\">CVE-2018-20020<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-20019\">CVE-2018-20019<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-15127\">CVE-2018-15127<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-15126\">CVE-2018-15126<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6307\">CVE-2018-6307<\/a><\/noindex>) sunt cauzate de supra\u00eenc\u0103rcarea buffer-ului \u0219i pot provoca poten\u021bial execu\u021bia de cod. 3 vulnerabilit\u0103\u021bi pot conduce la scurgeri de informa\u021bii, iar 2 la refuzul de a presta servicii.<br \/>\nToate problemele au fost deja remediat\u0103 de dezvoltatori, \u00eens\u0103 modific\u0103rile sunt reflectate numai <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/LibVNC\/libvncserver\/commit\/6073771eed1caf72f196e410182471e0dfd32149\">\u00een ramura master.<\/a><\/noindex> TightVNC<\/p>\n<p>\u00cen  <noindex><a rel=\"nofollow\" href=\"https:\/\/sourceforge.net\/projects\/vnc-tight\/\">(a fost testat\u0103 o ramur\u0103 \u00eenvechit\u0103 cross-platform, deoarece versiunea actual\u0103 2.x este disponibil\u0103 doar pentru Windows), au fost g\u0103site 4 vulnerabilit\u0103\u021bi. Trei probleme (<\/a><\/noindex> CVE-2019-15679 <noindex><a rel=\"nofollow\" href=\"https:\/\/www.tightvnc.com\/download-old.php\">1.3<\/a><\/noindex>CVE-2019-15678<noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2019-15679\">CVE-2019-8287<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2019-15678\">) sunt cauzate de supra\u00eenc\u0103rcarea buffer-ului \u00een func\u021biile InitialiseRFBConnection, rfbServerCutText \u0219i HandleCoRREBBP \u0219i pot provoca poten\u021bial execu\u021bia de cod. O problem\u0103 (<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-8287\">CVE-2019-15680<\/a><\/noindex>) duce la refuzul de a presta servicii. De\u0219i dezvoltatorii TightVNC au fost<noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2019-15680\">informa\u021bi<\/a><\/noindex>cu privire la probleme \u00eenc\u0103 de anul trecut, vulnerabilit\u0103\u021bile r\u0103m\u00e2n nerezolvate. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2018\/12\/10\/5\">\u00cen pachetul cross-platform<\/a><\/noindex> TurboVNC<\/p>\n<p>(fork-ul TightVNC 1.3, care utilizeaz\u0103 biblioteca libjpeg-turbo), a fost g\u0103sit\u0103 o singur\u0103 vulnerabilitate ( <noindex><a rel=\"nofollow\" href=\"https:\/\/www.turbovnc.org\/\">CVE-2019-15683<\/a><\/noindex> ), dar este periculoas\u0103 \u0219i, \u00een cazul \u00een care exist\u0103 acces autentificat la server, ofer\u0103 posibilitatea de a executa propriul cod, deoarece prin supra\u00eenc\u0103rcarea buffer-ului se poate controla adresa de \u00eentoarcere. Problema a fost rezolvat\u0103<noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2019-15683\">23 august<\/a><\/noindex>\u0219i nu se manifest\u0103 \u00een versiunea actual\u0103 <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/TurboVNC\/turbovnc\/commit\/cea98166008301e614e0d36776bf9435a536136e\">Pavel Cheremushkin de la Laboratorul Kaspersky a analizat diverse implement\u0103ri ale sistemului.<\/a><\/noindex> Pavel Cheremushkin de la Laboratorul Kaspersky a analizat diverse implement\u0103ri ale sistemului. <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/TurboVNC\/turbovnc\/releases\">2.2.3<\/a><\/noindex>.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Sursa: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51922\">opennet.ro<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0430\u0432\u0435\u043b \u0427\u0435\u0440\u0435\u043c\u0443\u0448\u043a\u0438\u043d \u0438\u0437 \u041b\u0430\u0431\u043e\u0440\u0430\u0442\u043e\u0440\u0438\u0438 \u041a\u0430\u0441\u043f\u0435\u0440\u0441\u043a\u043e\u0433\u043e \u043f\u0440\u043e\u0430\u043d\u0430\u043b\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043b \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0434\u043e\u0441\u0442\u0443\u043f\u0430 VNC (Virtual Network Computing) \u0438 \u0432\u044b\u044f\u0432\u0438\u043b 37 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0432\u044b\u0437\u0432\u0430\u043d\u043d\u044b\u0445 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u043c\u0438 \u043f\u0440\u0438 \u0440\u0430\u0431\u043e\u0442\u0435 \u0441 \u043f\u0430\u043c\u044f\u0442\u044c\u044e. \u0412\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0435 \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f\u0445 VNC-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u0442\u043e\u043b\u044c\u043a\u043e \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c, \u0430 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u043c \u043a\u043e\u0434\u0435 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u044b \u043f\u0440\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u043a \u0441\u0435\u0440\u0432\u0435\u0440\u0443, \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u0443\u0435\u043c\u043e\u043c\u0443 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u043e\u043c. \u041d\u0430\u0438\u0431\u043e\u043b\u044c\u0448\u0435\u0435 \u0447\u0438\u0441\u043b\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-53107","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0430\u0432\u0435\u043b \u0427\u0435\u0440\u0435\u043c\u0443\u0448\u043a\u0438\u043d \u0438\u0437 \u041b\u0430\u0431\u043e\u0440\u0430\u0442\u043e\u0440\u0438\u0438 \u041a\u0430\u0441\u043f\u0435\u0440\u0441\u043a\u043e\u0433\u043e \u043f\u0440\u043e\u0430\u043d\u0430\u043b\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043b \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u044b.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/37-uyazvimostej-v-razlichnyh-realizatsiyah-vnc\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd4737 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f\u0445 VNC | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0430\u0432\u0435\u043b \u0427\u0435\u0440\u0435\u043c\u0443\u0448\u043a\u0438\u043d \u0438\u0437 \u041b\u0430\u0431\u043e\u0440\u0430\u0442\u043e\u0440\u0438\u0438 \u041a\u0430\u0441\u043f\u0435\u0440\u0441\u043a\u043e\u0433\u043e \u043f\u0440\u043e\u0430\u043d\u0430\u043b\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043b \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u044b.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/37-uyazvimostej-v-razlichnyh-realizatsiyah-vnc\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-23T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:00:58+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd4737 vulnerabilit\u0103\u021bi \u00een diverse implement\u0103ri VNC | ProHoster","description":"Pavel Cheremushkin de la Laboratorul Kaspersky a analizat diverse implement\u0103ri ale sistemului.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/37-uyazvimostej-v-razlichnyh-realizatsiyah-vnc","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd4737 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f\u0445 VNC | ProHoster","og:description":"\u041f\u0430\u0432\u0435\u043b \u0427\u0435\u0440\u0435\u043c\u0443\u0448\u043a\u0438\u043d \u0438\u0437 \u041b\u0430\u0431\u043e\u0440\u0430\u0442\u043e\u0440\u0438\u0438 \u041a\u0430\u0441\u043f\u0435\u0440\u0441\u043a\u043e\u0433\u043e \u043f\u0440\u043e\u0430\u043d\u0430\u043b\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043b \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u044b.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/37-uyazvimostej-v-razlichnyh-realizatsiyah-vnc","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-23T21:00:00+00:00","article:modified_time":"2020-02-18T11:00:58+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"53107","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 06:07:23","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:31:28","updated":"2026-01-24 06:07:23","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/53107","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=53107"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/53107\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=53107"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=53107"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=53107"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}