CVE Vulnerabilities

CVE-2002-1336

Published: Dec 11, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

TightVNC before 1.2.6 generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.

Affected Software

NameVendorStart VersionEnd Version
TightvncTightvnc1.2.0 (including)1.2.0 (including)
TightvncTightvnc1.2.1 (including)1.2.1 (including)
TightvncTightvnc1.2.3 (including)1.2.3 (including)
TightvncTightvnc1.2.4 (including)1.2.4 (including)
TightvncTightvnc1.2.5 (including)1.2.5 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Linux 7.0RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.2RedHat*
Red Hat Linux 7.3RedHat*
Red Hat Linux 8.0RedHat*

References