Title: RealVNC Security Type Enforcement Failure Remote Authentication Bypass
Info
Disclosure
May 15, 2006
Discovery
Unknown
Dates
Exploit
May 15, 2006
Solution
Unknown
Description
RealVNC contains a flaw that may allow a malicious user to bypass authentication and allows access to the remote system without requiring knowledge of the VNC password. The issue is triggered due to an error within the handling of VNC password authentication requests. This flaw may lead to a loss of confidentiality.
Classification
Location:
Remote / Network Access
Attack Type:
Authentication Management
Impact:
Loss of Confidentiality
Exploit:
Exploit Public,
Exploit Commercial
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Upgrade to version 4.1.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.