CVE-2006-2450: High severity LibVNCServer LibVNCServer vulnerability
auth.c in LibVNCServer 0.7.1 allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, a different issue than CVE-2006-2369.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2450?
CVE-2006-2450 has been classified with a moderate severity level due to the potential for remote authentication bypass.
How do I fix CVE-2006-2450?
To address CVE-2006-2450, update to a version of LibVNCServer beyond 0.7.1 that resolves this vulnerability.
What systems are affected by CVE-2006-2450?
CVE-2006-2450 specifically affects LibVNCServer version 0.7.1.
What kind of attacks are possible due to CVE-2006-2450?
Attackers can exploit CVE-2006-2450 to bypass authentication by specifying an insecure security type.
Is CVE-2006-2450 related to other vulnerabilities?
CVE-2006-2450 is related to CVE-2006-2369, as both involve authentication issues within LibVNCServer.