Description TightVNC vncviewer 中存在一个堆缓冲区溢出漏洞。此漏洞是由于 rfbproto.c 文件中 InitialiseRFBConnection 中缺少整数值验证导致的。
References https://www.nsfocus.net/vulndb/63673 https://avd.aliyun.com/detail?id=AVD-2022-23967 https://github.com/MaherAzzouzi/CVE-2022-23967 https://www.sonicwall.com/blog/tightvnc-heap-buffer-overflow-vulnerability https://fortiguard.fortinet.com/encyclopedia/ips/51210 https://vuldb.com/?id.191698 https://www.juniper.net/us/en/threatlabs/ips-signatures/detail.VNC:OVERFLOW:TIGHTVNC-INIT-RFB.html https://www.vicarius.io/vsociety/products/22246_54721/tightvnc https://www.cybersecurity-help.cz/vdb/vulns/60162/ https://nvd.nist.gov/vuln/detail/CVE-2022-23967 https://feedly.com/cve/vendors/tightvnc https://www.suse.com/security/cve/CVE-2022-23967.html
Related VulnerabilitiesPoCCVE-2019-17662: ThinVNC 1.0b1 - Authentication BypassPoCCVE-2021-3654: Nova noVNC - Open RedirectPoCCVE-2022-25226: ThinVNC - Authentication BypassPoCCVE-2021-3654: noVNC Open RedirectPoCunauth-vnc-server-detect: Unauthenticated VNC Server - DetectPoCnovnc-login-panel: noVNC Login Panel - DetectVNC 未授权访问漏洞VNC 远程桌面系统默认口令漏洞VNC 远程桌面系统弱口令漏洞ThinVNC 目录穿越导致文件读取(CVE-2019-17662)