VDB
CVE-2011-1775
CVE-2011-1775
PUBLISHED
CVSS 5.800000190734863 MEDIUM
The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.
EPSS 1.29% · 67.5th percentile
Risk Scores
CVSS 2.0
5.800000190734863
EPSS Score
1.29%
67.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| tigervnc | tigervnc | 1.1 |
Timeline
- May 26, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 9, 2023 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
References
- [tigervnc-devel] 20110505 Re: potential vulnerability in TLS secType? mailing-list
- https://bugzilla.redhat.com/show_bug.cgi?id=702672 url
- https://bugzilla.redhat.com/show_bug.cgi?id=702470 url
- RHSA-2011:0871 vendor-advisory
- 47738 vdb
- http://lists.fedoraproject.org/pipermail/package-announce/2011-May/060567.html technical
- http://openwall.com/lists/oss-security/2011/05/06/2 technical
- http://openwall.com/lists/oss-security/2011/05/09/7 technical
- http://www.mail-archive.com/tigervnc-devel%40lists.sourceforge.net/msg01345.html technical
- https://nvd.nist.gov/vuln/detail/CVE-2011-1775 advisory
- http://secunia.com/advisories/44939 url
- http://www.mail-archive.com/tigervnc-devel%40lists.sourceforge.net/msg01342.html url
- http://www.mail-archive.com/tigervnc-devel@lists.sourceforge.net/msg01342.html url
- http://www.mail-archive.com/tigervnc-devel@lists.sourceforge.net/msg01345.html url
- http://www.mail-archive.com/tigervnc-devel@lists.sourceforge.net/msg01347.html url