=========================================================================Ubuntu Security Notice USN-5965-1
March 21, 2023

tigervnc vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 ESM

Summary:

TigerVNC could be made to expose sensitive information over the network.

Software Description:
- tigervnc: High-performance, platform-neutral implementation of VNC 

Details:

It was discovered that TigerVNC mishandled TLS certificate exceptions. An
attacker could use this vulnerability to impersonate any server after a client
had added an exception and obtain sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 ESM:
  tigervnc-common                 1.10.1+dfsg-3ubuntu0.1+esm2
  tigervnc-scraping-server        1.10.1+dfsg-3ubuntu0.1+esm2
  tigervnc-standalone-server      1.10.1+dfsg-3ubuntu0.1+esm2

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5965-1
  CVE-2020-26117

Ubuntu 5965-1: TigerVNC vulnerability

March 21, 2023
TigerVNC could be made to expose sensitive information over the network.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 ESM: tigervnc-common 1.10.1+dfsg-3ubuntu0.1+esm2 tigervnc-scraping-server 1.10.1+dfsg-3ubuntu0.1+esm2 tigervnc-standalone-server 1.10.1+dfsg-3ubuntu0.1+esm2 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5965-1

CVE-2020-26117

Severity
March 21, 2023

Package Information

Related News