37 bofokoli lits'ebetsong tse fapaneng tsa VNC

Pavel Cheremushkin oa Kaspersky Lab hlahlobisitsoe lits'ebetso tse fapaneng tsa VNC (Virtual Network Computing) sistimi ea phihlello e hole le ho tsebahatsa bofokoli ba 37 bo bakoang ke mathata ha o sebetsa ka mohopolo. Bofokoli bo bonoang ts'ebetsong ea li-server tsa VNC bo ka sebelisoa feela ke mosebelisi ea netefalitsoeng, 'me litlhaselo tsa bofokoli ho khoutu ea moreki lia khoneha ha mosebelisi a hokela ho seva e laoloang ke mohlaseli.

Palo e kholo ea bofokoli e fumanoeng ka har'a sephutheloana LITLHAKU TSE KHOLO, e fumaneha feela bakeng sa sethala sa Windows. Kakaretso ea likotsi tse 22 li fumanoe ho UltraVNC. Bofokoli ba 13 bo ka lebisa ho ts'ebetsong ea khoutu tsamaisong, 5 ho lutla mohopolong, le 4 ho hana ts'ebeletso.
Bofokoli bo kentsoeng tokollong 1.2.3.0.

Laebraring e bulehileng LibVNC (LibVNCServer le LibVNCClient), eo e sebelisoa ho VirtualBox, bofokoli ba 10 bo fumanoe.
5 bofokoli (CVE-2018-20020, CVE-2018-20019, CVE-2018-15127, CVE-2018-15126, CVE-2018-6307) li bakoa ke ho phalla ha buffer 'me ho ka lebisa ho ts'ebetsong ea khoutu. Bofokoli ba 3 bo ka lebisa ho lutla ha tlhahisoleseling, 2 ho hana ts'ebeletso.
Mathata ohle a se a lokisitsoe ke bahlahisi, empa liphetoho li ntse li le teng bonahatsa feela lekaleng la master.

В LebohangVNC (lekoa le lekoa la lekala la lefa la sefapano 1.3, kaha mofuta oa hajoale oa 2.x o lokollotsoe Windows feela), bofokoli bo 4 bo ile ba sibolloa. Mathata a mararo (CVE-2019-15679, CVE-2019-15678, CVE-2019-8287) li bakoa ke ho phalla ha buffer ho InitialiseRFBConnection, rfbServerCutText, le HandleCoRREBBP mesebetsi, 'me e ka lebisa ho ts'ebetsong ea khoutu. Bothata bo le bong (CVE-2019-15680) e lebisa ho hanetsoeng ha tšebeletso. Leha bahlahisi ba TightVNC ba ne ba tsebisitsoe mabapi le mathata selemong se fetileng, bofokoli bo lula bo sa lokisoe.

Ka har'a sephutheloana sa sethala TSOANG TSOANG (foroko ea TightVNC 1.3 e sebelisang laeborari ea libjpeg-turbo), ho fumanoe kotsi e le 'ngoe feela (CVE-2019-15683), empa e kotsi 'me, haeba u na le phihlelo e tiisitsoeng ho seva, e etsa hore ho khonehe ho hlophisa ts'ebetsong ea khoutu ea hau, kaha haeba buffer e phalla, ho ka khoneha ho laola aterese ea ho khutla. Bothata bo rarollotsoe 23 Aug 'me ha e hlahe tokollong ea hajoale 2.2.3.

Source: opennet.ru

Eketsa ka tlhaloso