Vulnerability CVE-2020-26117: Information

Description

In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.

Severity: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Published: Sept. 27, 2020
Modified: Nov. 16, 2022
Error type identifier: CWE-295

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
tigervncsisyphus1.10.1-alt41.13.1-alt2ALT-PU-2020-3339-1261954Fixed
tigervncsisyphus_e2k1.11.0-alt11.13.1-alt2ALT-PU-2022-3491-1-Fixed
tigervncp101.10.1-alt41.10.1-alt5ALT-PU-2020-3339-1261954Fixed
tigervncp91.10.1-alt51.10.1-alt5ALT-PU-2021-1185-1265009Fixed
tigervncc10f11.13.1-alt21.13.1-alt2ALT-PU-2024-3843-3342557Fixed
tigervncc9f21.13.1-alt21.13.1-alt2ALT-PU-2024-1936-3340033Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:tigervnc:tigervnc:*:*:*:*:*:*:*:*
      End excliding
      1.11.0

      Configuration 2

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*