37 ubungozi ekusetshenzisweni okuhlukahlukene kwe-VNC

UPavel Cheremushkin ovela eKaspersky Lab kuhlaziywe ukusetshenziswa okuhlukahlukene kwesistimu yokufinyelela kude ye-VNC (Virtual Network Computing) futhi kukhonjwe ubungozi obungu-37 obubangelwa izinkinga uma usebenza ngenkumbulo. Ubungozi obuhlonzwe ekusetshenzisweni kweseva ye-VNC bungaxhashazwa kuphela umsebenzisi ogunyaziwe, futhi ukuhlaselwa kobungozi bekhodi yeklayenti kungenzeka uma umsebenzisi exhuma kuseva elawulwa umhlaseli.

Inombolo enkulu yobungozi etholwe kuphakheji I-UltraVNC, itholakalela inkundla ye-Windows kuphela. Isamba esingu-22 sokuba sengozini kukhonjwe ku-UltraVNC. Ubungozi obuyi-13 bungase buholele ekwenziweni kwekhodi kusistimu, 5 ekuvuzeni kwenkumbulo, kanye noku-4 ekunqatshelweni kwesevisi.
Ubungozi bulungisiwe ekukhishweni 1.2.3.0.

Kumtapo wolwazi ovuliwe I-LibVNC (LibVNCServer kanye ne-LibVNCClient), okuyinto isetshenzisiwe ku-VirtualBox, ubungozi obuyi-10 bakhonjiwe.
5 ubuthakathaka (I-CVE-2018-20020, I-CVE-2018-20019, I-CVE-2018-15127, I-CVE-2018-15126, I-CVE-2018-6307) zibangelwa ukuchichima kwebhafa futhi kungaholela ekusebenzeni kwekhodi. 3 ubungozi kungaholela ekuvuzeni kolwazi, 2 ekunqatshelweni kwesevisi.
Zonke izinkinga sezilungisiwe ngabathuthukisi, kepha izinguquko zisalungiswa kubonakala kuphela ku-master branch.

Π’ TightVNC (ihlolwe igatsha lefa lenkundla yesiphambano 1.3, njengoba inguqulo yamanje engu-2.x ikhishelwa i-Windows kuphela), kutholwe ubungozi obu-4. Izinkinga ezintathu (I-CVE-2019-15679, I-CVE-2019-15678, I-CVE-2019-8287) zibangelwa ukuchichima kwebhafa kokuthi InitialiseRFBConnection, rfbServerCutText, kanye nemisebenzi ye-HandleCoRREBBP, futhi ingase iholele ekusebenziseni ikhodi. Inkinga eyodwa (I-CVE-2019-15680) kuholela ekunqatshelweni kwenkonzo. Yize abathuthukisi be-TightVNC bebekhona azisiwe mayelana nezinkinga ngonyaka odlule, ukukhubazeka kusalokhu kungalungiswa.

Ephaketheni le-cross-platform I-TurboVNC (imfoloko ye-TightVNC 1.3 esebenzisa umtapo wezincwadi we-libjpeg-turbo), kutholakale ubungozi obubodwa (I-CVE-2019-15683), kodwa kuyingozi futhi, uma unokufinyelela okuqinisekisiwe kuseva, kwenza kube lula ukuhlela ukukhishwa kwekhodi yakho, ngoba uma isilondolozi sichichima, kungenzeka ukulawula ikheli lokubuyisela. Inkinga isixazululiwe I-23 Aug futhi ayiveli ekukhishweni kwamanje 2.2.3.

Source: opennet.ru

Engeza amazwana