CVE-2002-1511: Medium severity Att Vnc vulnerability
Published Mar 3, 2003
·Updated
The vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to generate weak cookies.
Affected Software
11 affected components
Att Vnc=3.3.3
Att Vnc=3.3.3r2
Att Vnc=3.3.4
Att Vnc=3.3.5
Att Vnc=3.3.6
TightVNC TightVnc=1.2.0
TightVNC TightVnc=1.2.1
TightVNC TightVnc=1.2.2
TightVNC TightVnc=1.2.3
TightVNC TightVnc=1.2.4
TightVNC TightVnc=1.2.5
Remediation
Patch Available
Event History
Mar 3, 2003
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1511?
CVE-2002-1511 is classified as a moderate severity vulnerability due to the weak cookie generation that could lead to unauthorized access.
2
How do I fix CVE-2002-1511?
To fix CVE-2002-1511, upgrade to a version of VNC that is 3.3.3r2-21 or later, or use a patched version.
3
What software is affected by CVE-2002-1511?
CVE-2002-1511 affects versions of AT&T VNC prior to 3.3.3r2-21 and certain versions of TightVNC.
4
What are the consequences of exploiting CVE-2002-1511?
Exploiting CVE-2002-1511 can allow an attacker to gain unauthorized access to a VNC session due to weak cookie security.
5
Is CVE-2002-1511 still a risk in modern systems?
While CVE-2002-1511 primarily affects older VNC versions, any outdated systems running these versions are still at risk.