In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.
References
Configurations
History
No history.
Information
Published : 2020-09-27 04:15
Updated : 2024-11-21 05:19
NVD link : CVE-2020-26117
Mitre link : CVE-2020-26117
CVE.ORG link : CVE-2020-26117
JSON object : View
Products Affected
tigervnc
- tigervnc
debian
- debian_linux
opensuse
- leap
CWE
CWE-295
Improper Certificate Validation