Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Gentoo: GLSA-202309-18 High: LibVNCServer Authentication Risk

gentoo
Calendar Grey August 4, 2006
Scroller Gentoo
Critical security alert for Gentoo Linux concerning a vulnerability in LibVNCServer, enabling potential unauthorized entry due to authentication flaws.
VNC servers created with LibVNCServer accept insecure protocol types, even when the server does not offer it, resulting in unauthorized access to the server

Summary

Gentoo Linux Security Advisory GLSA 200608-05 https://security.gentoo.org/ Severity: High Title: LibVNCServer: Authentication bypass Date: August 04, 2006 Bugs: #136916 ID: 200608-05

Synopsis ======= VNC servers created with LibVNCServer accept insecure protocol types, even when the server does not offer it, resulting in unauthorized access to the server.
Background ========= LibVNCServer is a GPL'ed library for creating VNC servers.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/libvncserver < 0.8.2 >= 0.8.2
========== LibVNCServer fails to properly validate protocol types effectively letting users decide what protocol to use, such as "Type 1 - No...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround