CVE-2020-26117
published 2020-09-27CVE-2020-26117: In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as…
PriorityP342high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
EPSS
3.06%
86.1th percentile
In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | tigervnc | < tigervnc 1.10.1+dfsg-9 (bookworm) | tigervnc 1.10.1+dfsg-9 (bookworm) |
| opensuse | leap | — | — |
| tigervnc | tigervnc | < 1.11.0 | 1.11.0 |
| tigervnc | tigervnc | >= 0 < 1.10.1+dfsg-9 | 1.10.1+dfsg-9 |
| tigervnc | tigervnc | >= 0 < 1.10.1+dfsg-9 | 1.10.1+dfsg-9 |
| tigervnc | tigervnc | >= 0 < 1.10.1+dfsg-9 | 1.10.1+dfsg-9 |
| tigervnc | tigervnc | >= 0 < 1.10.1+dfsg-9 | 1.10.1+dfsg-9 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cx25-8g49-fx7q: In rfb/CSecurityTLS
ghsa_unreviewed·2022-05-24
CVE-2020-26117 [HIGH] CWE-295 GHSA-cx25-8g49-fx7q: In rfb/CSecurityTLS
In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.
OSV
CVE-2020-26117: In rfb/CSecurityTLS
osv·2020-09-27·CVSS 8.1
CVE-2020-26117 [HIGH] CVE-2020-26117: In rfb/CSecurityTLS
In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.
Ubuntu
TigerVNC vulnerability
vendor_ubuntu·2023-03-21
CVE-2020-26117 TigerVNC vulnerability
Title: TigerVNC vulnerability
Summary: TigerVNC could be made to expose sensitive information over the network.
It was discovered that TigerVNC mishandled TLS certificate exceptions. An
attacker could use this vulnerability to impersonate any server after a client
had added an exception and obtain sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
tigervnc: certificate exceptions stored as authorities
vendor_redhat·2020-09-18·CVSS 8.1
CVE-2020-26117 [HIGH] CWE-296 tigervnc: certificate exceptions stored as authorities
tigervnc: certificate exceptions stored as authorities
In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.
Mitigation: This flaw can be mitigated by not making certificate exceptions in the affected versions of tigervnc, and therefore they will not be stored as authorities.
Package: tigervnc (Red Hat Enterprise Linux 6) - Out of support scope
Package: tigervnc (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2020-26117: tigervnc - In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, vie...
vendor_debian·2020·CVSS 8.1
CVE-2020-26117 [HIGH] CVE-2020-26117: tigervnc - In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, vie...
In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.
Scope: local
bookworm: resolved (fixed in 1.10.1+dfsg-9)
bullseye: resolved (fixed in 1.10.1+dfsg-9)
forky: resolved (fixed in 1.10.1+dfsg-9)
sid: resolved (fixed in 1.10.1+dfsg-9)
trixie: resolved (fixed in 1.10.1+dfsg-9)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00024.htmlhttps://bugzilla.opensuse.org/show_bug.cgi?id=1176733https://github.com/TigerVNC/tigervnc/commit/20dea801e747318525a5859fe4f37c52b05310cbhttps://github.com/TigerVNC/tigervnc/commit/7399eab79a4365434d26494fa1628ce1eb91562bhttps://github.com/TigerVNC/tigervnc/commit/b30f10c681ec87720cff85d490f67098568a9cbahttps://github.com/TigerVNC/tigervnc/commit/f029745f63ac7d22fb91639b2cb5b3ab56134d6ehttps://github.com/TigerVNC/tigervnc/releases/tag/v1.11.0https://lists.debian.org/debian-lts-announce/2020/10/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00024.htmlhttps://bugzilla.opensuse.org/show_bug.cgi?id=1176733https://github.com/TigerVNC/tigervnc/commit/20dea801e747318525a5859fe4f37c52b05310cbhttps://github.com/TigerVNC/tigervnc/commit/7399eab79a4365434d26494fa1628ce1eb91562bhttps://github.com/TigerVNC/tigervnc/commit/b30f10c681ec87720cff85d490f67098568a9cbahttps://github.com/TigerVNC/tigervnc/commit/f029745f63ac7d22fb91639b2cb5b3ab56134d6ehttps://github.com/TigerVNC/tigervnc/releases/tag/v1.11.0https://lists.debian.org/debian-lts-announce/2020/10/msg00007.html
2020-09-27
Published