CVE-2020-26117: High severity tigervnc vulnerability
Published Sep 27, 2020
·Updated
In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.
Affected Software
3 affected components
TigerVNC TigerVNC<1.11.0
Debian Debian Linux=9.0
openSUSE Leap=15.2
Remediation
Event History
Sep 27, 2020
CVE Published
via MITRE·03:30 AM
Data Sourced
via MITRE·03:30 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-26117?
CVE-2020-26117 is considered a high-severity vulnerability due to the potential for certificate impersonation.
2
How do I fix CVE-2020-26117?
To mitigate CVE-2020-26117, upgrade TigerVNC to version 1.11.0 or later.
3
What versions of TigerVNC are affected by CVE-2020-26117?
TigerVNC versions prior to 1.11.0 are affected by CVE-2020-26117.
4
Which operating systems are impacted by CVE-2020-26117?
CVE-2020-26117 affects TigerVNC on various platforms, including Debian 9.0 and openSUSE Leap 15.2.
5
What are the implications of CVE-2020-26117 for users?
Users may be at risk of man-in-the-middle attacks, as the vulnerability allows attackers to impersonate servers.