Page 3 of 21 results (0.002 seconds)

CVSS: 5.9EPSS: 0%CPEs: 1EXPL: 0

26 May 2011 — The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate. La función CSecurityTLS::processMsg en common/rtb/CSecurityTLS.cxx en el componente vncviewer en tigervnc v1.1beta1 no verifica de forma adecuada el certificado X.509 del servidor, lo que permite a ataques de Hombre en medio (man-in-the-midd... • http://lists.fedoraproject.org/pipermail/package-announce/2011-May/060567.html • CWE-20: Improper Input Validation •