CVE-2002-1336: High severity tightvnc tightvnc vulnerability
Published Dec 11, 2002
·Updated
TightVNC before 1.2.6 generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.
Affected Software
5 affected components
TightVNC TightVnc=1.2.4
TightVNC TightVnc=1.2.0
TightVNC TightVnc=1.2.1
TightVNC TightVnc=1.2.3
TightVNC TightVnc=1.2.5
Event History
Dec 11, 2002
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1336?
CVE-2002-1336 is considered a high-severity vulnerability due to its potential for allowing unauthorized remote access.
2
How do I fix CVE-2002-1336?
To fix CVE-2002-1336, upgrade TightVNC to version 1.2.6 or later to ensure unique challenge strings for each connection.
3
Which versions of TightVNC are affected by CVE-2002-1336?
TightVNC versions 1.2.0 through 1.2.5 are affected by CVE-2002-1336.
4
What type of attack does CVE-2002-1336 enable?
CVE-2002-1336 enables remote attackers to bypass VNC authentication by sniffing challenge and response data.
5
Is it safe to use TightVNC versions prior to 1.2.6 due to CVE-2002-1336?
No, using TightVNC versions prior to 1.2.6 is not safe due to the vulnerability allowing potential unauthorized access.