SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#117929

RealVNC Server does not validate client authentication method

Overview

The RealVNC Server fails to properly authenticate clients. This may allow a remote attacker to bypass authentication and gain access to the VNC server.

I. Description

The Virtual Network Computing (VNC) Protocol

According to RealVNC, "The VNC protocol is a simple protocol for remote access to graphical user interfaces."

RealVNC

RealVNC is an implementation of the VNC protocol.

The Problem

The RealVNC Server fails to properly authenticate clients. When a RealVNC client connects to a RealVNC server, the server provides a list of supported authentication methods. By design, the client then selects a method from the list. Due to an implementation flaw, if the client specifies that no (null) authentication should be used, the server accepts this method and authenticates the client, whether or not null authentication was offered by the server.

Note that exploit code for this vulnerability is publicly available.

II. Impact

A remote, unauthenticated attacker could gain access to a system running RealVNC server. If the RealVNC server runs with administrative privileges, the attacker could gain complete control of the system.

III. Solution

Upgrade

This issue is corrected in RealVNC version 4.1.2, RealVNC Personal Edition 4.2.3, and RealVNC Enterprise Edition 4.2.3. Refer to the RealVNC Downloads site to get a patched version.

Prompt Local Users to Accept Connections

Until updates can be applied, selecting the Prompt local user to accept connections option may prevent attackers from gaining a VNC session by exploiting this vulnerability. See the authentication section of the RealVNC user guide for more information.

Systems Affected

VendorStatusDate Updated
RealVNCVulnerable16-May-2006
Red Hat, Inc.Not Vulnerable17-May-2006

References


http://www.realvnc.com/howitworks.html
http://www.realvnc.com/products/free/4.1/winvnc.html#Security
http://www.realvnc.com/products/free/4.1/release-notes.html
http://www.realvnc.com/products/personal/4.2/release-notes.html
http://www.realvnc.com/products/enterprise/4.2/release-notes.html
http://marc.theaimsgroup.com/?l=bugtraq&m=114771408013890&w=2

Credit

This vulnerability was reported by James Evans.

This document was written by Jeff Gennari.

Other Information

Date Public05/15/2006
Date First Published05/16/2006 10:20:39 AM
Date Last Updated02/26/2008
CERT Advisory 
CVE Name 
US-CERT Technical Alerts 
Metric30.49
Document Revision47

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader