37 kusagadzikana mune dzakasiyana siyana VNC kuita

Pavel Cheremushkin kubva kuKaspersky Lab analysed kushandiswa kwakasiyana-siyana kweVNC (Virtual Network Computing) kureba kwekuwana system uye yakaratidza kusakwana makumi matatu nenomwe kunokonzerwa nematambudziko kana uchishanda nendangariro. Kusagadzikana kwakaonekwa muVNC server kuita kunogona chete kushandiswa nemushandisi ane chokwadi, uye kurwiswa kwekusagadzikana mukodhi yemutengi kunogoneka kana mushandisi akabatana neseva inodzorwa neanorwisa.

Huwandu hukuru hwekusagadzikana hunowanikwa mupasuru UltraVNC, inowanikwa chete yeWindows platform. Huwandu hwemakumi maviri nembiri hwekusagadzikana hwakaonekwa muUltraVNC. 22 kusasimba kunogona kutungamira mukutevedzwa kwekodhi pane sisitimu, 13 kune ndangariro inodonha, uye 5 mukuramba sevhisi.
Kusagadzikana kwakagadziriswa mukuburitswa 1.2.3.0.

Muraibhurari yakashama LibVNC (LibVNCServer uye LibVNCClient), iyo inoshandiswa ne muVirtualBox, 10 kusasimba kwakaonekwa.
5 kushaya simba (CVE-2018-20020, CVE-2018-20019, CVE-2018-15127, CVE-2018-15126, CVE-2018-6307) inokonzerwa nekufashukira kwebhafa uye inogona kutungamira kukuita kodhi. 3 kusasimba kunogona kutungamira kune ruzivo rwekuburitswa, 2 mukuramba sevhisi.
Matambudziko ese akatogadziriswa nevagadziri, asi shanduko dzichiri reflected chete mubazi ratenzi.

Π’ TightVNC (yakaedzwa cross-platform legacy bazi 1.3, sezvo yazvino vhezheni 2.x yakaburitswa yeWindows chete), 4 kusasimba kwakawanikwa. Matambudziko matatu (CVE-2019-15679, CVE-2019-15678, CVE-2019-8287) zvinokonzerwa nekuwanda kwebuffer muInitialiseRFBConnection, rfbServerCutText, uye HandleCoRREBBP mabasa, uye inogona kutungamira kukuita kodhi. Dambudziko rimwe chete (CVE-2019-15680) kunotungamirira kukunyimwa basa. Kunyangwe ivo vagadziri veTightVNC vaive notified nezvematambudziko gore rapfuura, kusasimba kunoramba kusingagadziriswe.

Muchinjika-chikuva package TurboVNC (forogo yeTightVNC 1.3 inoshandisa libjpeg-turbo library), kusagadzikana kumwe chete kwakawanikwa (CVE-2019-15683), asi zvine ngozi uye, kana iwe uine chokwadi chekusvika kune sevha, zvinoita kuti zvikwanise kuronga kuitiswa kwekodhi yako, nekuti kana buffer ikafashukira, zvinokwanisika kudzora kero yekudzoka. Dambudziko rakagadziriswa 23 Aug uye haioneki mukuburitswa kwazvino 2.2.3.

Source: opennet.ru

Voeg