Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-1775

EPSS 0.48% · P65
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2011-1775

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
TigerVNC证书验证安全绕过漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
TigerVNC 1.1beta1版本的vncviewer组件中存在安全绕过漏洞,由于common/rfb/CSecurityTLS.cxx中的CSecurityTLS::processMsg函数不能正确验证服务器X.509证书。中间人攻击者可以借助任意证书欺骗TLS VNC服务器。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2011-1775

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-1775

Please Login to view more intelligence information

Same Patch Batch · n/a · 2011-05-26 · 14 CVEs total

CVE-2010-2246Daniel Friesel feh '--wget-timestamp'远程代码执行漏洞
CVE-2011-1758Fedoraproject System Security Services Daemon Automatic Ticket Renewal Credentials Cache文件
CVE-2010-4251Linux kernel net/core/sock.c套接字实现拒绝服务漏洞
CVE-2010-4805Linux kernel net/core/sock.c套接字实现拒绝服务漏洞
CVE-2010-4806IBM Web Content Manager程序编写工具权限许可和访问控制漏洞
CVE-2010-4807IBM Web Content Manager无限递归查询漏洞
CVE-2011-1581Linux kernel drivers/net/bonding/bond_main.c bond_select_queue函数输入验证错误漏洞
CVE-2011-1801Google Chrome Popup Blocker安全绕过漏洞
CVE-2011-1804WebKit 输入验证错误漏洞
CVE-2011-1806Google Chrome GPU命令缓冲区内存破坏漏洞
CVE-2011-1807Google Chrome Blob处理越界远程代码执行漏洞
CVE-2011-2172IBM WebSphere Portal Search Center跨站脚本攻击漏洞
CVE-2011-2173IBM WebSphere Portal OutputMediator对象实现拒绝服务漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2011-1775

No comments yet


Leave a comment