ATT Labs VNC Vulnerable To Attack

Reported January 23, 2001, by CORE-SDI

VERSIONS AFFECTED
  • ATT Labs VNC

DESCRIPTION

ATT VNC, a freeware remote control package, uses a challenge and response mechanism for authenticating clients. A malicious attacker can use a design vulnerability in the VNC mechanism to launch a simple man-in-the-middle attack to gain unauthorized access to hosts running VNC.

VENDOR RESPONSE

ATT Labs has been contacted. It is recommended that you use VNC over cryptographically strong channels.

CREDIT

Discovered by CORE-SDI.

 
Hide comments

Comments

  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
Publish